
CVE-2007-2447-Exploitation-SIEM-Detection-Lab
Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

VAPT report for vsFTPd 2.3.4 backdoor CVE-2011-2523, covering Nmap vulnerability scanning, Metasploit exploitation, post-exploitation root access,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Cisco ASA Software and ASDM Security Research

PowerSploit - A PowerShell Post-Exploitation Framework

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin…

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

Azure Post Exploitation Framework

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Metasploit modules in testing

Know a plugin has a php object exploit but need to find which lib to use?

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.


All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

cs扫描ms17-010的一个插件