A proof‑of‑concept C2 framework that uses Server‑Sent Events (SSE) and the MCP protocol for agent registration, command dispatch, and result collection. By tunneling through ngrok, you can quickly expose your C2 server to the public internet for rapid testing and demonstration.
☆35Apr 28, 2025Updated last year
Alternatives and similar repositories for PhantomPipe
Users that are interested in PhantomPipe are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated last year
- Static Encrypt is an crate that encrypts string literals at compile time and only decrypted at runtime when needed.☆60Jan 17, 2026Updated 8 months ago
- Feed it a number. Your cloned voice does the social engineering, while you sip your coffee. A ghost that talks on the phone for you.☆126Jul 20, 2026Updated 2 months ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆86Jan 26, 2026Updated 7 months ago
- Okta Data Collector for BloodHound Community☆17Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆203Apr 27, 2026Updated 4 months ago
- NT AFD.sys file downloader (Windows 10/11 x64)☆39Mar 18, 2026Updated 6 months ago
- ☆20Jul 5, 2026Updated 2 months ago
- Aggressor script to automatically download and load an arsenal of open source and private Cobalt Strike tooling.☆46Aug 16, 2024Updated 2 years ago
- Exploit AD CS misconfiguration allowing privilege escalation and persistence from any child domain to full forest compromise☆135Dec 2, 2023Updated 2 years ago
- A harmless Netcat-lookalike for detection testing. Simulates NC-style command-line flags and listener behavior without exposing a real ba…☆37Nov 27, 2025Updated 9 months ago
- ☆13Jun 26, 2023Updated 3 years ago
- Interact with Windows RPC Services over SMB using go-smb☆11Jul 6, 2026Updated 2 months ago
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆176Jun 19, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- bring your own clean ntdll (or other MS dlls)☆28Jul 14, 2025Updated last year
- ☆38Apr 15, 2025Updated last year
- ☆106Jan 21, 2025Updated last year
- Windows rootkit designed to work with BYOVD exploits☆225Jan 18, 2025Updated last year
- ☆19Dec 18, 2024Updated last year
- Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensi…☆26Oct 27, 2025Updated 10 months ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 3 months ago
- Persist like a Dodder☆69May 19, 2025Updated last year
- AWSDoor is a red team automation tool designed to simulate advanced attacker behavior in AWS environments☆36Sep 17, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Indirect syscalls + DInvoke made simple.☆95Dec 24, 2024Updated last year
- This lightweight C# demo application showcases interactive remote shell access via named pipes and the SMB protocol.☆124Feb 21, 2025Updated last year
- Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled T…☆127Jan 24, 2026Updated 7 months ago
- AI-based implant feature☆25Apr 28, 2025Updated last year
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated last year
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆106Jan 10, 2026Updated 8 months ago
- M365 Conditional Access Policy Bypass OST (Offensive Tooling)☆50Apr 22, 2026Updated 5 months ago
- Evasive loader for .NET Framework assemblies☆51May 14, 2026Updated 4 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆463Jun 27, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A PoC Cobalt Strike UDRL written in Rust☆34Sep 12, 2026Updated last week
- Interactive program for loading AES encrypted shellcode with Dynamic Invocation, and interactive .NET assemblies in memory.☆13Mar 16, 2022Updated 4 years ago
- Modified version of PEAS client for offensive operations☆51May 18, 2026Updated 4 months ago
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 6 months ago
- ☆43Sep 9, 2023Updated 3 years ago
- Plantronics Desktop Hub LPE☆37May 15, 2024Updated 2 years ago
- ☆28Mar 14, 2026Updated 6 months ago