
SocialFish
Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

SecurityTube Linux Assembly Expert x86 Exam

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative…

CVE-2022-31147 is a path traversal flaw in matthiasmullie/minify. This guide helps security teams test for arbitrary file read on Linux and Windows…

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

Educational lab demonstrating EFS bypass (CVE-2021-43217) on Windows 10 using Kali Linux, Metasploit, and custom Python shellcode for penetration…

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

Python Remote Administration Tool (RAT)

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

EasySploit - Metasploit automation (EASIER and FASTER than EVER)

A simple bash based metasploit automation tool!

Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution

Whatsapp Automatic Payload Generator [CVE-2019-11932]

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

With the help of this docker image, you can easily access PEzor on your system!