
Empire
Empire is a PowerShell and Python post-exploitation agent.

Autonomous Hacking Agent for Red Team

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

A C2 post-exploitation framework

a guard that blocks catastrophic agent actions

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.


RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

PolicyKit CVE-2021-3560 Exploit (Authentication Agent)

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…