
Boomerang
Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Mass exploitation tool for CVE-2024-4358, executing commands on multiple web targets concurrently with threading support.

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

Automated mass exploitation tool for CVE-2019-16920 command injection vulnerability in multiple D-Link routers, enabling unauthenticated remote code…

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

SSHPry v2 - Spy & Control os SSH Connected client's TTY

Improved POC for CVE-2022-1388 that affects multiple F5 products.

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

Proof-of-concept exploit for unauthenticated remote code execution in EMCO Software products via DNS spoofing and malicious update injection.

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

Open-source C2 integration framework providing a unified web interface for managing multiple command-and-control instances, listeners, agents, and…

Exploit for CVE-2024-3273, supports single and multiple hosts

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Python exploit for CVE-2018-7600 (Drupalgeddon 2) enabling remote code execution on Drupal 7 with multiple injection methods and predefined commands…

Linux bash script automation for metasploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]