
PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

PoCs and exploits for CVEs discovered by NebuSec.

Adversary Emulation Framework

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

Local privilege escalation exploit for Windows HTTP.sys integer overflow (CVE-2026-62735), demonstrating crash and full SYSTEM shell via nonpaged…

Detector and proof-of-concept local privilege escalation for the Linux algif_aead page-cache scratch-write vulnerability (CVE-2026-31431). Includes…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Exploit for CVE-2026-0828 targeting Safetica ProcessMonitorDriver.sys to terminate processes and spawn a SYSTEM shell.

Ghidra is a software reverse engineering (SRE) framework

Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.