
SteppingStones
Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

The SpecterOps project management and reporting engine

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Active HTTP fingerprinting algorithm and tool that sends 8 crafted probes to generate unique, reversible server profiles for threat detection, server…

Exploit for CVE-2026-58057 targeting Flowise Windows RCE via case-sensitive environment variable validation bypass. Supports reverse shell,…

Unauthenticated RCE exploit for WordPress Bricks Builder (CVE-2024-25600) with interactive shell, reverse shells, file transfer, mass scanning,…

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

CLI scanner for CVE-2025-55182 and CVE-2025-66478 in Next.js apps, enabling remote command execution, system reconnaissance, and automated…

Live Feed of C2 servers, tools, and botnets

PowerShell rebuilt in C# for Red Teaming purposes

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR