
Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit
This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If…
Integrated platforms for developing, executing, and managing penetration tests.

This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Crystal Palace Evasion kit for Sliver

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework…

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

AI 驱动的 SOC 仿真平台

Workflow automation for Security Teams

ABYSS C2 — HiSilicon DVR Exploit Framework (CVE-2020-25078). Educational IoT security research platform.

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

A simple C2 Framework written in modern C++

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

Air-gapped cybersecurity assistant for security professionals. 100% offline AI-powered analysis tool for Nmap, Volatility, BloodHound, Metasploit,…

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)