
CVE-2025-54914-PoC
Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Red Team K8S Adversary Emulation Based on kubectl

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

DejaVU - Open Source Deception Framework

Data from a BRAWL Automated Adversary Emulation Exercise

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Kali365 - EvilTokens Replica

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

MinIO Information Disclosure Vulnerability scanner by metasploit

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.


All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A collection of awesome penetration testing resources, tools and other shiny things

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

autonomous red teaming platform; multi-agent offensive-security meta-harness