
ExecuteAssembly
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

ASTROID v 1.2 bypass most A.V softwares

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

PostShell - Post Exploitation Bind/Backconnect Shell

Yet Another PHP Shell - The most complete PHP reverse shell

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

SharpSploit is a .NET post-exploitation library written in C#

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Assist reverse tcp shells in post-exploration tasks

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

indirect syscalls for AV/EDR evasion in Go assembly

Golang reverse/bind shell generator