
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Establish secure remote access to a machine with interactive shell, file transfer, and web proxy over end-to-end encrypted peer-to-peer WebRTC, using…

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)


A Modular Penetration Testing Framework

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Network Pivoting Toolkit

CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.

A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

CVE-2021-31800 POC

Metasploit Auxiliary module for scanning and detecting CVE-2020-0796 (SMBGhost) vulnerability in Windows SMBv3 implementations.

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

Python-Based Pentesting CLI Tool