
KittyStager
KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Cobalt Strike HTTPS beaconing over Microsoft Graph API

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

Protocol agnostic online password guessing API.

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers

Zimbra RCE simple poc

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Command and Control server on Slack

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

C# tool for exfiltrating files over DNS using XOR and asymmetric encryption, designed for red team engagements with restricted outbound connections.

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

simple bash script for exploit CVE-2021-31166

Hooked browser communication over MQTT

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781). Executes arbitrary commands on vulnerable…

Python3 implementation for exploiting Log4J over Jolokia