
Maverick
Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

venom - C2 shellcode generator/compiler/handler

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.

Rust-based User-Defined Reflective Loader for Cobalt Strike payloads. Avoids RWX memory pages for OPSEC safety. Includes an extractor tool for loader…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Rust Weaponization for Red Team Engagements.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Nano is a family of PHP web shells which are code golfed for stealth.


C# implementations of shellcode injection techniques including classic injection, thread hijacking, process hollowing, and atom bombing, using…

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

Automatically spawn a reverse shell fully interactive for Linux or Windows victim