
RATel
RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

Python-based exploit tool for CVE-2025-25257 in FortiWeb. Automates SQL injection detection, webshell upload, and remote command execution on…

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…

Client-server tool for remotely loading and executing Java bytecode via ClassLoader and Reflect API, with ChaCha20 encryption and keepalive…

HVNC for Cobalt Strike

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

Script that exploits the vulnerability that allows establishing a backdoor in the UnrealIRCd service with CVE-2010-2075

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

Freedom Fighting Mode: open source hacking harness

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine…