
Ninja
Open source C2 server created for stealth red team operations

Open source C2 server created for stealth red team operations

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

An interactive CLI application for interacting with authenticated Jupyter instances.

POC for CVE-2024-29973

Work in Progress. RAT written in C++ using wxWidgets

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

Autonomous and modular system for network based information gathering and exploitation. WEB interface here: https://antecursor.fr/ More info…

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

Python proof-of-concept for unauthenticated OS command injection in TOTOLINK N600R, exploiting the langType parameter to execute arbitrary commands…

Suite for reverse shell handling geared toward working within the native shell

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

A swiss army knife for pentesting networks

GitHub Self-Hosted Runner Enumeration and Attack Tool

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…