
Persistnux
Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Peirates - Kubernetes Penetration Testing tool

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

go CVE-2026-31431 (CopyFail) local privilege escalation exploit

Proof-of-concept exploits for CVE-2024-21626, a Docker/runc container escape vulnerability, demonstrating multiple attack vectors to access and…

Golang rewrite of the Copy Fail (CVE-2026-31431) local privilege escalation exploit, corrupting page cache to gain root on Linux systems.

Add go CVE-2026-43284 / CVE-2026-43500 (dirtyfrag) local privilege escalation exploit

Analyzes and exploits a container escape vulnerability in legacy Docker/runc versions, demonstrating fd leakage to access the host filesystem, with…

Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster

A vulnerability scanner for container images and filesystems

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Go-based exploit for CVE-2019-5736 (Runc container escape) with a customizable reverse shell payload, designed for penetration testing and red team…

A Linux Host-based Intrusion Detection System based on eBPF.

A script for exploiting CVE-2022-1227

Exploit CVE-2025-1974 with a single file.