
SillyRAT
A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

Covert backdoor transmission tool using 802.11 probe request and beacon frames for isolated network attacks. Delivers payloads via HID devices,…

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

Python-based exploit for CVE-2018-1273 (Spring Data Commons RCE) with interactive command shell and HTTP POST payload injection for penetration…

Source code for a BPFDoor backdoor controller supporting TCP, UDP, ICMP, and HTTPS covert communication channels with magic packet activation,…

Python exploit for CVE-2022-22947 (Spring Cloud Gateway RCE) with command execution, reverse shell, and vulnerability detection via Actuator API SpEL…

Exploit for CVE-2020-11651 (SaltStack) with batch scanning, remote command execution, and shell compatibility fixes. Supports multi-threaded target…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Python exploit for CVE-2025-32433 targeting Erlang OTP SSH server. Sends crafted SSH packets to open a reverse shell and gain root access.

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…