
Aggressor-Aggregator
A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.
A cross platform C2/post-exploitation framework.

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege


The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Specify targets and run sets of tools against them

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

A collection of selenium tests that might aid it takeover of a selenium node

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines


Technical Reference to multiple relay techniques

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host