NimPlant is a lightweight, first-stage Command and Control (C2) implant written in Nim, designed to provide a flexible and efficient solution for remote access and control. It offers a range of features, including a small footprint, easy deployment, and customizable communication protocols, making it an attractive option for penetration testers and red teamers. With its modular architecture and extensible design, NimPlant can be easily integrated with other tools and frameworks, allowing users to tailor their C2 infrastructure to specific needs and environments.
FEATURES
SIMILAR TOOLS
Ivy is a payload creation framework for executing arbitrary VBA source code directly in memory, utilizing programmatical access to load, decrypt, and execute shellcode.
A tool for automated security scanning of web applications and manual penetration testing.
CrossC2 enables generation of cross-platform payloads for CobaltStrike, enhancing operational flexibility.
CLI tool for offensive and defensive security assessments on the Joi validator library with a wide range of attacks.
An open-source security tool that simulates network breaches by self-propagating across data centers to test organizational resilience against lateral movement attacks.
A proof-of-concept tool that demonstrates automated MFA bypass techniques for Microsoft Outlook through browser automation and request interception.
A simple, fast web crawler for discovering endpoints and assets in a web application
A blog post discussing the often overlooked dangers of CSV injection in applications.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.