03 Aug 2026
C#
★ 81
DecryptRDCManager is a .NET tool designed to decrypt credentials stored in Remote Desktop Manager (.rdg) files, leveraging the functionality of RDCMan.DLL. Its primary use case is to extract and read encrypted user credentials, particularly those contained within the more reliable `<credentialsProfile>` section, while also providing an option to automate file detection via user settings. Notable features include the ease of building the tool and its ability to handle paths for .rdg files seamlessly, along with a focus on credential profile extraction for enhanced reliability.
03 Aug 2026
Python
★ 36
DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.
03 Aug 2026
Python
★ 47
Crowbar is a comprehensive Windows post-exploitation tool designed to facilitate various tasks such as privilege escalation and system command execution via PowerShell. It includes an extensive range of scripts and utilities, notably the 'Hail Mary' feature for launching multiple scripts simultaneously, and checks for the presence of Windows Subsystem for Linux on the target machine. The tool is actively maintained, with regular updates that introduce new scripts and enhancements to improve functionality.
03 Aug 2026
C#
★ 22
Coyote is a C# post-exploitation implant designed for maintaining access to compromised Windows systems during red team operations. Its notable features include bypassing application whitelisting through InstallUtil.exe, utilizing a recursive DNS tunnel to retrieve encrypted commands, and maintaining a small footprint on both memory and network resources. The tool leverages a DLL that periodically polls a DNS TXT record for remote instructions, allowing operators to execute various payloads, such as spawning a reverse shell, while potentially evading detection.
03 Aug 2026
Go
★ 435
Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.
03 Aug 2026
PowerShell
★ 13
The Cobalt Strike Aggressor Script Collection provides a set of scripts designed to enhance post-exploitation capabilities within the Cobalt Strike framework. Key features include techniques for privilege escalation, persistence, and situational awareness, along with accessible notes that facilitate streamlined operations during engagements. This tool is primarily used by security professionals for advanced exploitation and operational efficiency in red team scenarios.
03 Aug 2026
Python
★ 58
The C2 Server is a Command and Control framework that enables attackers to manage compromised target machines through a reverse shell connection. It supports various commands for file management, directory navigation, and even malicious functions like keylogging and credential spoofing, enhancing the attacker's ability to interact with the victim's system. Written in Python, it provides a user-friendly interface for executing predefined commands and extracting sensitive information from infected devices.
03 Aug 2026
Python
★ 50
Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.
03 Aug 2026
Python
★ 205
Bella is a potent post-exploitation and remote administration tool designed specifically for macOS, leveraging Python for high-level automation and ease of use. Its primary use case involves establishing SSL/TLS encrypted reverse shells to facilitate comprehensive data extraction, including passwords, system information, and iCloud services, while offering features like multi-user support, reverse VNC connections, and extensive logging capabilities. Notably, Bella can gain root access to expand its functionalities and maintain persistent control over the target system, all while operating undetectably.
03 Aug 2026
Python
★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.
03 Aug 2026
★ 279
Awesome Malware is a curated repository of various malware, botnets, and post-exploitation tools designed for research and educational purposes. It offers extensive categories such as analysis tools, banking trojans, C2 frameworks, credential stuffing checkers, and more, enabling users to explore and understand malicious software dynamics. Noteworthy features include a focus on free software projects and the inclusion of both historical and contemporary malware resources for comprehensive analysis.
03 Aug 2026
★ 20
autoMetasploit is a Ruby script designed to streamline the processes of scanning, exploiting, and conducting post-exploitation activities with Metasploit. It automates key tasks by requiring configuration of plugins and supports report generation by integrating with external templates and email functionalities. Notable features include customizable brute force scripts, LDAP user enumeration capabilities, and the ability to send PDF reports via email.
03 Aug 2026
C#
★ 212
AtlasC2 is a C# command and control (C2) framework designed for Stage 1 operations, primarily used for establishing footholds within Windows environments and executing C# payloads through HTTP-based implants. Notable features include the ability to manage listeners, connect to multiple implants, execute system commands via PowerShell or CMD, and dynamically load C# assemblies into memory, making it a potent tool for post-exploitation scenarios despite current OPSEC limitations.
03 Aug 2026
Python
★ 435
AdbNet is an exploitation tool designed for identifying and compromising vulnerable Android devices across the globe. Key features include post-exploitation modules, device scanning functionalities, IP address management, and integration with APIs from Censys and Shodan for discovering susceptible devices. Users can connect to these devices through common ports, execute commands, and utilize various exploits to gain control over the target systems.
03 Aug 2026
Python
★ 163
Ghost Framework is an Android post-exploitation tool that leverages the Android Debug Bridge for remote device administration. It provides a user-friendly interface to execute various remote management tasks such as accessing the device shell, installing applications, capturing screenshots, and managing device settings. Notable features include password removal capabilities and comprehensive system information retrieval.
03 Aug 2026
JavaScript
★ 142
ZeroPulse is a modern Command & Control (C2) platform designed for secure remote management and monitoring of systems, utilizing Cloudflare Tunnel technology for encrypted connections. Key features include built-in authentication, support for WinRM and SSH interactions, a responsive React interface with real-time terminal integration, and comprehensive DNS management. The tool is currently in active development and is intended primarily for testing and evaluation purposes.
03 Aug 2026
Go
★ 395
XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.
03 Aug 2026
C
★ 287
WindowSpy is a Cobalt Strike Beacon Object File designed for targeted user surveillance, facilitating stealthy detection of significant user activities such as entering credentials or accessing confidential documents. It operates by comparing active window titles against a customizable list to trigger specific actions, like screenshots, only when relevant activities are detected, thus minimizing unnecessary data collection. Key features include easy integration with Cobalt Strike, a configurable keyword list for triggering surveillance, and the ability to customize the actions performed upon detection.
03 Aug 2026
C
★ 166
WebcamBOF is a Beacon Object File (BOF) for Cobalt Strike that enables webcam capture functionality. Its primary use case is to facilitate remote image acquisition by allowing users to save webcam images either to disk or download them directly over the Cobalt Strike beacon. Notable features include multiple save methods, including capturing images as screenshots, and the ability to enumerate connected webcam devices.
03 Aug 2026
Python
★ 76
Venus is a VS Code extension designed to serve as an agent for the Mythic C2 framework, enabling operators to create and deliver payloads to target systems. This tool automates the packaging of VS Code extensions and supports various commands for interacting with the system environment, although it currently lacks support for encrypted payloads. Notably, Venus is cross-platform compatible and requires manual installation on target machines after preparation.
03 Aug 2026
C
★ 10
Unicorn is a Command and Control (C2) framework designed for post-exploitation and remote control operations. Built using Python and Flask, it features a client-server architecture that supports multiple listeners, dynamic command execution, and client chat synchronization, while still being in development with planned enhancements such as a proxy server and GUI integration. This tool is aimed at cybersecurity professionals for managing agents and executing commands in compromised environments.
03 Aug 2026
★ 28
The FreeZeroDays/TTPs repository serves as a curated collection of offensive security notes, focusing on Tactics, Techniques, and Procedures (TTPs). It provides a repository of validated commands and resources targeted towards researchers and practitioners in offensive security. Notably, the documentation emphasizes accuracy and reliability, and it draws inspiration from other established collections in the field.
03 Aug 2026
Python
★ 294
Sshimpanzee is a tool for creating a static reverse SSH server that initiates connections from the victim machine to an attacker's IP, bypassing the need for incoming connection requests. It provides all standard SSH functionalities, including port forwarding and dynamic SOCKS proxies, while also offering advanced tunneling methods like DNS Tunneling, ICMP Tunneling, and HTTP encapsulation to facilitate communication in restrictive network environments. Notable features include customizable build configurations, support for multiple tunneling mechanisms, and the ability to generate new SSH keys upon build.
03 Aug 2026
Go
★ 11
SoundShell is a Command-and-Control (C2) tool developed in Go that utilizes the Spotify Web API to execute encoded commands and generate corresponding playlists. Its primary use case is to dynamically create playlists based on user-inputted commands, with notable features including custom command execution, command encoding for playlist generation, and random track selection from a predefined song pool.
03 Aug 2026
Go
★ 10
Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.