
pwncat
Post-exploitation platform automating enumeration, privilege escalation, persistence, and C2 operations via reverse/bind shells with cross-platform…

Post-exploitation platform automating enumeration, privilege escalation, persistence, and C2 operations via reverse/bind shells with cross-platform…

Modular cloud penetration testing framework with teamserver-client architecture for reconnaissance, enumeration, exploitation, and post-exploitation…

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

C# implementation of WMI for remote process creation, VBS execution, file upload, and system enumeration with alternate credential support and AMSI…

Cobalt Strike BOFs for in-memory post-exploitation: Active Directory enumeration, clipboard capture, WiFi credential dump, port scan, and registry…

Telegram bot-based C2 framework for remote system control, file exfiltration, screen/webcam capture, and service enumeration with stealthy deployment.

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

HTA-based post-exploitation shell for breakout assessments. Provides file explorer, system reconnaissance, AD enumeration, and file transfer…

Automated CVE-2020-5902 detection and exploitation tool for F5 BIG-IP TMUI, supporting single/batch vulnerability checks, file read/write, user…

Exploit scripts for BMC BladeLogic RSCD agent vulnerabilities, enabling remote code execution, password changes, and user enumeration on Linux and…

Step-by-step walkthrough exploiting CVE-2023-30258 (MagnusBilling RCE) and escalating privileges via fail2ban misconfiguration on a TryHackMe lab.…

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Exploit and post-exploitation framework for Next.js RSC (CVE-2025-55182), with interactive RCE, file transfer, persistence, enumeration, and privesc.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Penetration testing framework with AI-driven decision engine