
Citadel
Collection of pentesting scripts

An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized…

Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural…

A tool to abuse Exchange services

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Yet Another PHP Shell - The most complete PHP reverse shell

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Go shellcode loader that combines multiple evasion techniques

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Execute shellcode files with rundll32

pinky - The PHP mini RAT (Remote Administration Tool)

PostShell - Post Exploitation Bind/Backconnect Shell