
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…

WIP Post-exploitation framework tailored for hypervisors.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Python Flask web server for capturing, processing, and logging encoded/encrypted payloads and tar archives, designed for penetration testers and red…

PoC and Docker lab for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via the commits API route bypass and urlencoded error…

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

Azure Post Exploitation Framework

Windows Remote Post Breach Tool via Telegram

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.

Freedom Fighting Mode: open source hacking harness

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

Arbitrary File Read and DoS in vendure-ecommerce exploit

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…