
cloudrasp-log4j2
一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.


venom - C2 shellcode generator/compiler/handler

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

GUI版 EXP

Metasploit exploit for the CVE-2025-50286.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

DeimosC2 is a Golang command and control framework for post-exploitation.

autonomous red teaming platform; multi-agent offensive-security meta-harness

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

NekoBot | Auto Exploiter With 500+ Exploit 2000+ Shell

Automatic SQL injection and database takeover tool

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.