


A collaborative, multi-platform, red teaming framework

Adversary Emulation Framework

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Decrypted content of eqgrp-auction-file.tar.xz

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

Exploitation Framework for ATtiny85 Based HID Attacks

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

Azure Post Exploitation Framework