
joro
A collaborative web exploitation framework.

A collaborative web exploitation framework.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

Go-based exploit development framework with built-in phases for target verification, version scanning, exploitation, and C2. Supports multiple…

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Penetration testing framework with AI-driven decision engine

Proof-of-concept exploit for CVE-2026-9277, a command injection vulnerability in shell-quote library. Performs recursive JSON traversal with…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Cacti Unauthenticated Command Injection

Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)

CVE-2026-24061

GUI-based scanner and exploit tool for CVE-2026-42588 (ActiveMQ RCE). Supports VPS payload delivery and DNSLog-based vulnerability verification with…

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.