A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-compatible, and built with evasion, anti-analysis and stability in mind. All capabilities are natively implemented from scratch.
☆23Mar 7, 2025Updated last year
Alternatives and similar repositories for Hydrangea-C2-Payloads
Users that are interested in Hydrangea-C2-Payloads are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 4 months ago
- ACE Analyzer for identifying ESC1-8 vulnerabilities (Written by AI)☆42Jul 4, 2026Updated 2 months ago
- Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.☆77Dec 10, 2025Updated 9 months ago
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆34Aug 4, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- rust clr heap encryption (https://github.com/lap1nou/CLR_Heap_encryption), but no heap encryption.☆17Jan 6, 2024Updated 2 years ago
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆86Jul 28, 2026Updated last month
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 8 months ago
- Scripts to interact with Microsoft Graph APIs☆47Nov 7, 2024Updated last year
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆80Dec 23, 2023Updated 2 years ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆117Updated this week
- Slides and resources from MCTTP 2025 Talk☆70Oct 26, 2025Updated 10 months ago
- rShellZ s a linux reverse-shell & exploitation assistance framework. With lots of payload and post exploitation modules.☆13Dec 13, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆69Jul 12, 2026Updated 2 months ago
- A curated collection of Living off the Land (LotL) attack demonstrations where trusted binaries go rogue, because if it didn’t launch cal…☆37Jan 7, 2026Updated 8 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- A shellcode loader generator with support for multiple injection techniques, built for red team engagements.☆100Jul 1, 2026Updated 2 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated 2 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- Agent for AdaptixC2 with focus in evasion, capability and malleable.☆224Apr 26, 2026Updated 4 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- Memory API proxy via signed mozglue.dll☆40Jun 25, 2026Updated 2 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Exploit for ToolShell☆15Nov 20, 2025Updated 10 months ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated 3 months ago
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 7 months ago
- Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shel…☆73Jun 24, 2026Updated 2 months ago
- Early cascade injection PoC based on Outflanks blog post written in Rust☆66Dec 26, 2025Updated 8 months ago
- Monarch - The Adversary Emulation Toolkit☆64Jan 7, 2025Updated last year
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆28May 21, 2026Updated 4 months ago
- DynLoader A modular Windows loader focused on EDR evasion Built with indirect syscall (Tartarus Gate / Hell’s Gate), Manual PE parsing …☆82Jul 10, 2026Updated 2 months ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Detect Remote Local Credentials Dumping using a Shadow Snapshot☆32Jan 27, 2025Updated last year
- poc for cve-2025-53772☆45Dec 10, 2025Updated 9 months ago
- ☆160Jun 20, 2026Updated 3 months ago
- A portable C# utility for enumerating local and remote windows sessions☆56Jan 1, 2026Updated 8 months ago
- A PoC Cobalt Strike UDRL written in Rust☆34Sep 12, 2026Updated last week
- Templates for developing your own listeners and agents for AdaptixC2.☆60Sep 6, 2026Updated 2 weeks ago
- Python based GUI for browsing LDAP☆184Jul 30, 2026Updated last month