
gopacket
A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

C# port of WMImplant which uses either CIM or WMI to query remote systems

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

tunnel port to port traffic over an obfuscated channel with AES-GCM encryption.

MeshDeck port for Arch Linux ARM - Wilson

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Penetration testing framework with AI-driven decision engine

A third-party Gopher Assassin for the Havoc Framework.

Practice Go programming and implement CobaltStrike's Beacon in Go

Follina MS-MSDT 0-day MS Office RCE (CVE-2022-30190) PoC in Go

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on…

Hershell is a simple TCP reverse shell written in Go.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…