
DynastyPersist
Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

We developed GRAT2 Command & Control (C2) project for learning purpose.

An information security preparedness tool to do adversarial simulation.

This uses CVE-2025-43407 as exploit and still testing working not gauranteed.

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Linux enumeration tool for pentesting and CTFs with verbosity levels

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Monitor linux processes without root permissions

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

Automated local privilege escalation exploit for CVE-2024-48990 (needrestart v3.7), leveraging PYTHONPATH hijacking to gain root access.

Poc for CVE-2025-7771 to modify PPL Protection

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

CVE-2024-5009 : WhatsUp Gold SetAdminPassword Privilege Escalation

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

# CVE-2025-27591 PoC — Below Local Privilege Escalation This repository contains a Proof of Concept (PoC) demonstrating the local privilege…

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…