
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…


Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Android Remote Access Trojan

The SteaLinG is an open-source penetration testing framework designed for social engineering

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

Windows Remote Access Trojan (RAT)

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Android remote administration tool

Code Roulette is a terminal interface based (TUI), online multiplayer, Russian Roulette game where the loser executes the winner's Python payload…

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

Tools for maintaining access to systems and proof-of-concept demonstrations.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

TeleShadow - Telegram Desktop Session Stealer (Windows)

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.