
SQLC2
SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

A Golang implant that uses Slack as a command and control server

A stealthy Python based Windows backdoor that uses Github as a command and control server

A fully featured Windows backdoor that uses Gmail as a C&C server

A fully featured Windows backdoor that uses email as a C&C server

A PoC backdoor that uses Gmail as a C&C server

A fully featured backdoor that uses Twitter as a C&C server

ICMP-based command-and-control tool that tunnels C2 traffic through firewalls using ping payloads, undetectable by most AV/EDR solutions.

Fileless Command Execution for Lateral Movement in Nim

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

A python reverse shell that uses DNS as the c2 channel

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…