Utilizng an MCP Server to communicate with your C2
☆95May 15, 2025Updated last year
Alternatives and similar repositories for Claude-C2
Users that are interested in Claude-C2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- A powerful, modular, lightweight and efficient command & control framework written in Nim.☆224Nov 3, 2025Updated 8 months ago
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆54May 16, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 6 months ago
- ZoomBotC2 is a stealthy Command and Control (C2) framework that leverages Zoom's API endpoints for covert communication between implants …☆57Jun 30, 2025Updated last year
- .NET tool used to enrich RPC telemetry☆103Jan 24, 2026Updated 6 months ago
- ClickForClickOnce - Generate configurable clickonce payloads☆97Apr 17, 2026Updated 3 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- BOF with Synthetic Stackframe☆258Oct 30, 2025Updated 8 months ago
- Python3 utility for creating zip files that smuggle additional data for later extraction☆275May 15, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Updated this week
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆219Feb 6, 2025Updated last year
- Reaping treasures from strings in remote processes memory☆288Feb 8, 2025Updated last year
- ☆152Nov 6, 2025Updated 8 months ago
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆65Jun 23, 2025Updated last year
- COM-based DLL Surrogate Injection☆186Dec 9, 2025Updated 7 months ago
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- ☆43Feb 18, 2025Updated last year
- Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or…☆42Dec 22, 2025Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- BOF to decrypt Signal Desktop chat logs☆70Feb 20, 2025Updated last year
- Fairy Law - Compromise or disable EDR security solutions☆79Dec 1, 2025Updated 7 months ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 10 months ago
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆301May 2, 2025Updated last year
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- BOF to steal Teams cookies☆132Nov 2, 2025Updated 8 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 6 months ago
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆237May 4, 2026Updated 2 months ago
- Sleep Obfuscation in Rust☆286Dec 1, 2025Updated 7 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆37Apr 15, 2025Updated last year
- Vectored Exception Handling Squared☆30Dec 27, 2025Updated 6 months ago
- Evasive loader for .NET Framework assemblies☆44May 14, 2026Updated 2 months ago
- Convert your shellcode into an ASCII string☆129Jun 27, 2025Updated last year
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆69Jan 5, 2026Updated 6 months ago
- find dll base addresses without PEB WALK☆170Jul 13, 2025Updated last year
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆58Apr 14, 2025Updated last year