
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Miscellaneous exploit code

CVE-2018-8120 Windows LPE exploit

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Python exploit for CVE-2023-30547 vm2 sandbox escape vulnerability. Generates base64-encoded JSON payload to open a reverse shell from vulnerable…

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Tools and Techniques for Red Team / Penetration Testing

All about bug bounty (bypasses, payloads, and etc)

The ultimate WinRM shell for hacking/pentesting

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Deserialization payload generator for a variety of .NET formatters

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers