
yara-ttd
Use YARA rules on Time Travel Debugging traces

Use YARA rules on Time Travel Debugging traces

LPE exploit for a UAF in Windows (CVE-2021-40449).

A third-party Gopher Assassin for the Havoc Framework.

Copy Fail - CVE-2026-31431

Trigger-only for CVE-2021-29627

Page Cache Exploit for CVE-2024-1065

Script to exploit CVE-2023-38035


Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

A Golang implant that uses Slack as a command and control server

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection