
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…
Tools for weaponizing vulnerabilities to gain unauthorized access to systems or data.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Java RMI security testing tool for detecting, enumerating, and exploiting insecure RMI services using ysoserial deserialization gadgets to achieve…

This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.

Ethereum recon and exploitation tool.

secator - the pentester's swiss knife

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Poc - CVE-2025-49132

Defeating Windows User Account Control

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Mediatek Flash and Repair Utility

The decompiled Morris Worm source code

用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。