
CHAOS
🔥 CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.

🔥 CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

Tools for maintaining access to systems and proof-of-concept demonstrations.

Uses Shodan API to pull down C2 servers to run known exploits on them.

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Generates TeamViewer ID and password payloads for remote access to target machines. Combines executable generation with third-party remote control…

Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE,…

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

Metasploit module for exploiting Veritas Backup Exec Agent SHA-auth NDMP vulnerability to achieve remote code execution.

Demonstrates remote code execution in Cassia Gateway firmware via unsanitized queueUrl parameter, allowing unauthenticated attackers to inject bash…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

Python Remote Administration Tool (RAT) to gain meterpreter session

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

Venom is a library that meant to perform evasive communication using stolen browser socket

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.