
Koi
Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Offensive Lua.

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

Bash simulator to control a server using PHP system functions.

This is a plugin for the c# R.A.T server providing extension to android based phone systems

C# RAT (Remote Administration Tool)

openssh-cve-2024-6387.sh

Exploiting Parsec for Windows to gain SYSTEM privileges

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

Tunnel TCP connections through a file

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Proof-of-concept exploit for CVE-2022-22029, a Windows NFS remote code execution vulnerability. Includes PowerShell commands to disable NFSV3 as a…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…