
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

The Browser Exploitation Framework Project

This is a webshell open source project

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.

Cobalt Strike Malleable C2 Design and Reference Guide

A PoC backdoor that uses Gmail as a C&C server

Practice Go programming and implement CobaltStrike's Beacon in Go

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

A malicious LDAP server for JNDI injection attacks

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Adaptive DLL hijacking / dynamic export forwarding

A fully featured backdoor that uses Twitter as a C&C server

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

A fully implemented kernel exploit for the PS4 on 5.05FW

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…