
endgame
ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

An all-in-one hacking tool to remotely take over Android devices.

JSON Web Token Hack Toolkit

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

An open-source post-exploitation framework for students, researchers and developers.

A blind XSS detection and XSS data capture framework

A collaborative web exploitation framework.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

Automatic SSTI detection tool with interactive interface

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

CVE-2026-50522 PoC