
PHP-REVERSE-SHELL
This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

Python-based exploit tool targeting CVE-2016-7144 for penetration testing and vulnerability validation against affected systems.

A collection of awesome penetration testing resources, tools and other shiny things

Post-exploitation tool for hiding processes from monitoring applications

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Gorsair gives root access on remote docker containers that expose their APIs

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

Obfuscated CVE-2024-6095 exploit script that uses random strings, advanced payloads, custom headers, and randomized delays to evade detection during…

Modified mimikatz binary with resource modification and digital signature to evade 360 Antivirus detection for credential dumping in penetration…