
Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.

For pentesters who don't wanna leave their terminals.

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

Create tar/zip archives that can exploit directory traversal vulnerabilities

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

CVE-2021-44228

👻 [PoC] CSV+ 0.8.0 - Arbitrary Code Execution (CVE-2022-21241)

Proof-of-concept exploit for CVE-2022-34919, demonstrating unauthenticated arbitrary file upload and RCE in Contensis CMS Classic interface via…

This is the exploit of CVE-2018-6574: go get RCE

A PowerShell armoury for security guys and girls

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

SSRF (Server Side Request Forgery) testing resources

A tool that implements the Golden SAML attack

a CLI for ephemeral penetration testing