
metarget
Automated framework for deploying vulnerable cloud-native infrastructures, enabling rapid installation of CVEs in Docker, Kubernetes, and Linux…

Automated framework for deploying vulnerable cloud-native infrastructures, enabling rapid installation of CVEs in Docker, Kubernetes, and Linux…

Deliberately vulnerable virtual machine designed as a target for practicing exploit development and penetration testing with Metasploit. Includes a…

Cross-platform HTTP/2 C2 server and agent for post-exploitation in containerized environments, featuring container breakout modules, Kubernetes CVE…

Dockerized vulnerable PhpCollab instance for practicing CVE-2017-6090 remote code execution with Metasploit integration and guided exploitation…

Agentless platform for discovering and managing VM security threats including vulnerabilities, malware, rootkits, misconfigurations, leaked secrets,…

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

Exploit and post-exploitation framework for Next.js RSC (CVE-2025-55182), with interactive RCE, file transfer, persistence, enumeration, and privesc.

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

Custom Metasploit module exploiting Kubernetes secret mount policy bypass (CVE-2023-2728, CVE-2024-3177) to retrieve secrets via crafted pods.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

AI-native security testing platform integrating 100+ tools with agentic orchestration, role-based testing, MCP-native tools, C2 capabilities, and…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

Automated Red Team Infrastructure deployement using Docker

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

Docker image bundling 200+ offensive security tools for rapid penetration testing, reconnaissance, exploitation, and vulnerability assessment with…