
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

An open-source post-exploitation framework for students, researchers and developers.


Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Adversary Emulation Framework

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

All about bug bounty (bypasses, payloads, and etc)

A list of interesting payloads, tips and tricks for bug bounty hunters.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Covenant is a collaborative .NET C2 framework for red teamers.

Search for ROP gadgets in ELF, PE, Mach-O, and Raw binaries across x86, ARM, MIPS, and RISC-V architectures. Supports automated ROP chain generation…

PowerShell Obfuscator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Python Remote Administration Tool (RAT)