
AggressorScripts
Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Collection of pentesting scripts

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

Collection of bypass gadgets to extend and wrap ysoserial payloads

Curated collection of image-based payloads for authorized red-team testing and security education, with HTML examples for generating or embedding web…

A collection of scripts for dealing with Cobalt Strike beacons in Python

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Collection of payloads for exploiting the Log4j remote code execution vulnerability (CVE-2021-44228), including JNDI injection strings and bypass…

Curated collection of payloads for ethical security testing and bug bounty hunting, covering common web vulnerabilities and attack vectors.

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Exploit scripts for CVE-2024-28397, a js2py sandbox escape that executes arbitrary Python code to spawn a reverse shell on a target endpoint.