
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

A collection of AWS penetration testing junk

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

The SteaLinG is an open-source penetration testing framework designed for social engineering

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

Python Flask web server for capturing, processing, and logging encoded/encrypted payloads and tar archives, designed for penetration testers and red…

A network data locater using credentials obtained during penetration tests

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…