
Elite
Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Python exploit for CVE-2022-36804, a command injection in Atlassian Bitbucket Server and Data Center, enabling remote code execution with read…

Proof-of-concept exploit for Apache Spark command injection (CVE-2022-33891) with check and reverse shell modes, enabling authorized security testing.

CVE-2025-59376, CVE-2025-59377

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

Go-based proof-of-concept exploit for CVE-2023-5044 in ingress-nginx, enabling authenticated remote command execution by creating crafted Kubernetes…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

Python exploit for CVE-2022-36804 command injection in Atlassian Bitbucket Server, enabling remote code execution and reverse shell with customizable…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Proof-of-concept exploit for CVE-2025-54123, a critical authenticated command injection in Hoverfly <= 1.11.3, enabling remote code execution via the…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Docker projects to retain beacon source IPs using C2 relaying infra