
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

The patching of Android kernel and Android system

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Go package that aids in binary analysis and exploitation

A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.

SambaCry exploit and vulnerable container (CVE-2017-7494)

CVE-2020-28502 node-XMLHttpRequest RCE

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

Exploit for the vulnerability CVE-2024-43044 in Jenkins

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Java-based exploit for CVE-2024-20931 bypassing CVE-2023-21839 patch in Oracle WebLogic. Uses JNDI injection via ForeignOpaqueReference to achieve…

TP-Link TL-WR1043ND - Authenticated Remote Code Execution

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.