
hayduk
Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Detector and proof-of-concept for a Linux kernel page-cache write vulnerability (CVE-2026-31431) in algif_aead, including a non-destructive scanner…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Cisco ASA Software and ASDM Security Research

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin…

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Metasploit modules in testing

Know a plugin has a php object exploit but need to find which lib to use?

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

cs扫描ms17-010的一个插件

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

A repository that contains all the working PoC I have crafted for known CVEs, and details on any ongoing research I am currently doing (mostly Iot…

AI-powered offensive security testing using autonomous agents, directly in your terminal.