#1Adversary simulation, red team infrastructure, C2 frameworks, and operational security tools.
Kitploit recommended

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit

In-memory token vault BOF for Cobalt Strike

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

Welcome to the Doggie and EvilDoggie repository by Faraday Security! Doggie is a modular DIY CAN Bus to serial adapter (USB, BLE, UART) using the…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

Passive UAC elevation using dll infection

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

Proof-of-concept exploit for CVE-2023-25194, a JNDI injection vulnerability in Apache Kafka Connect enabling remote code execution via crafted…

🌒 Shell command obfuscation to avoid detection systems

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

POC and Scanner for CVE-2023-24055