
PentestGPT
Automated Penetration Testing Agentic Framework Powered by Large Language Models

Automated Penetration Testing Agentic Framework Powered by Large Language Models

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

PoCs and exploits for CVEs discovered by NebuSec.

P4wnP1 A.L.O.A. by MaMe82 is a framework which turns a Rapsberry Pi Zero W into a flexible, low-cost platform for pentesting, red teaming and…

An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Linux kernel privilege escalation exploits targeting Netfilter's nf_table module, developed by Team Orca for multiple CVEs.

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…