
killshot
A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

An evil RAT (Remote Administration Tool) for macOS / OS X.

iOS/macOS/Linux Remote Administration Tool

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…


A tool to generate media files with malicious metadata

A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

Tool to manipulate and weaponize Office Open XML documents.

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

An XSS exploitation command-line interface and payload generator.

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…