
Java-Deserialization-Scanner
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

A tool that is used to hunt vulnerabilities in x64 WDM drivers

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…


A list of custom Metasploit modules you can use for penetration testing.

Ghidra is a software reverse engineering (SRE) framework

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have…

Covenant is a collaborative .NET C2 framework for red teamers.

P4wnP1 A.L.O.A. by MaMe82 is a framework which turns a Rapsberry Pi Zero W into a flexible, low-cost platform for pentesting, red teaming and…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

AdaptixC2 is a highly modular advanced redteam toolkit

Starkiller is a Frontend for PowerShell Empire.