
getsploit
Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Decrypted content of eqgrp-auction-file.tar.xz

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Dirty Pipe root exploit for Android (Pixel 6)

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Automating Host Exploitation with AI

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

CLI tool to search CVEs and exploits from NIST, ExploitDB, and GitHub databases. Supports exploit compilation detection and lists latest critical…