ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via .NET's DLR.
☆178Feb 14, 2026Updated 6 months ago
Alternatives and similar repositories for Atomic-Red-Team-C2
Users that are interested in Atomic-Red-Team-C2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Run PowerShell command without invoking powershell.exe☆36Nov 22, 2021Updated 4 years ago
- Spray a hash via smb to check for local administrator access☆143Feb 7, 2021Updated 5 years ago
- AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Co…☆233Feb 15, 2021Updated 5 years ago
- BoobSnail allows generating Excel 4.0 XLM macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation.☆256Mar 6, 2025Updated last year
- Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)☆143Oct 31, 2017Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it …☆155Apr 27, 2021Updated 5 years ago
- Shellcode runner in GO that incorporates shellcode encryption, remote process injection, block dlls, and spoofed parent process☆227Jul 30, 2020Updated 6 years ago
- Use current thread token to execute command☆15Jan 27, 2021Updated 5 years ago
- ABUSING WINDOWS TELEMETRY FOR PERSISTENCE☆140Jul 2, 2020Updated 6 years ago
- A collection of various tools for red-teaming exercises. A mix of C#, Powershell, & Python☆106Jul 26, 2024Updated 2 years ago
- This tool enables the compilation of a C# program that will execute arbitrary PowerShell code, without launching PowerShell processes thr…☆193Jul 26, 2020Updated 6 years ago
- Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.☆289Jun 8, 2026Updated 2 months ago
- C# port of WMImplant which uses either CIM or WMI to query remote systems☆204Jul 14, 2021Updated 5 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆90Aug 26, 2021Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Iterative AD discovery toolkit for offensive operations☆84Mar 16, 2020Updated 6 years ago
- Toolbox containing research notes & PoC code for weaponizing .NET's DLR☆526Jan 21, 2022Updated 4 years ago
- Vampire is an aggressor script which integrates with BloodHound to mark nodes as owned.☆78Apr 6, 2021Updated 5 years ago
- Load any Beacon Object File using Powershell!☆261Dec 9, 2021Updated 4 years ago
- Extended Process List (Search functionality)☆28Jan 23, 2021Updated 5 years ago
- Core bypass Windows Defender and execute any binary converted to shellcode☆44Oct 12, 2021Updated 4 years ago
- Apply a filter to the events being reported by windows event logging☆265Apr 24, 2021Updated 5 years ago
- 从入门到放弃的产物,学习过程中用python实现的一个单点c2基本功能☆11Mar 11, 2020Updated 6 years ago
- Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS head…☆597Jul 26, 2021Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies☆324Apr 8, 2023Updated 3 years ago
- Self-developed tools for Lateral Movement/Code Execution☆723Aug 17, 2021Updated 4 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆219Jul 14, 2021Updated 5 years ago
- Just a PoC to turn xlsx (regular Excel files) into xlsm (Excel file with macro) and slipping inside a macro (vbaProject.bin)☆144Sep 4, 2021Updated 4 years ago
- Pass the Hash to a named pipe for token Impersonation☆145May 1, 2021Updated 5 years ago
- 后渗透持久化控制平台; Windows Persistence Platform;☆46Sep 16, 2021Updated 4 years ago
- A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.☆442Apr 1, 2022Updated 4 years ago
- Excel Macro Document Reader/Writer for Red Teamers & Analysts☆522May 19, 2026Updated 2 months ago
- A method of bypassing EDR's active projection DLL's by preventing entry point exection☆1,171Mar 31, 2021Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- cobalt strike 自用脚本☆28Oct 29, 2020Updated 5 years ago
- (kinda) Malicious Outlook Reader☆137Mar 3, 2021Updated 5 years ago
- POCs for Shellcode Injection via Callbacks☆415Feb 23, 2021Updated 5 years ago
- Standalone version of my AES Powershell payload for Cobalt Strike.☆111Dec 27, 2019Updated 6 years ago
- Public Repo for Atomic Test Harness☆290Apr 8, 2025Updated last year
- A Flask-based HTTP(S) command and control (C2) with a web frontend. Malleable agent written in Go.☆37Aug 12, 2023Updated 3 years ago
- Bypass AMSI and Executing PowerShell scripts from C# - using CyberArk's method to bypass AMSI☆29Feb 22, 2020Updated 6 years ago