
Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation
End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Exploiting HID VertX and EDGE access control systems

Metasploit auxiliary module that identifies Emby Media Server version and exploits CVE-2020-26948 SSRF vulnerability to scan internal network…

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

Intranet penetration tools

TrojanDropper/PS.Maloader.d

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Rapid Assessment of Web Resources

针对类似CVE-2017-10271漏洞的一个java反序列化漏洞扫描器

MeshDeck port for Arch Linux ARM - Wilson

Maltego Penetration Testing Transforms

Universal Dynamic Virtual Channel connector for Remote Desktop Services

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…