
HERCULES
HERCULES is a special payload generator that can bypass antivirus softwares.

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

ScareCrow - Payload creation framework designed around EDR bypass.

Cloak can backdoor any python script with some tricks.

Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.

The LAZY script will make your life easier, and of course faster.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

CVE-2022-31147 is a path traversal flaw in matthiasmullie/minify. This guide helps security teams test for arbitrary file read on Linux and Windows…

High-fidelity RCE scanner for CVE-2025-55182 affecting Next.js RSC. Supports mass scanning, command execution, and automated recon pipelines. Built…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Covenant is a collaborative .NET C2 framework for red teamers.

Undetectable Windows Payload Generation