
Ivy
Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Adversary Emulation Framework

Explotation framework for CVE-2019-11687

A Framework meant for the exploitation of iOS devices.

Python-based proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Core RCE on Apache Tomcat. Uploads a JSP webshell with…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

A framework for constructing self-spreading binaries

Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Covenant is a collaborative .NET C2 framework for red teamers.

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

A wrapper for MSFvenom that allows for easy generation of payloads

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE