
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Curated collection of payloads for ethical security testing and bug bounty hunting, covering common web vulnerabilities and attack vectors.

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

A collection of scripts for dealing with Cobalt Strike beacons in Python

Exploit scripts for CVE-2024-28397, a js2py sandbox escape that executes arbitrary Python code to spawn a reverse shell on a target endpoint.

AD CS exploitation related stuff goes here

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Collection of bypass gadgets to extend and wrap ysoserial payloads

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…