
ezXSS
Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…


A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Remote Java classpath enumeration via deserialization

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

Exploit for Apache Tomcat CGI Servlet RCE (CVE-2019-0232) on Windows, featuring auto enumeration, CGI path fuzzing, interactive HTTP shell, and…

Two-stage RCE exploit chain for Silentium HTB machine, combining user enumeration via password reset bug with JavaScript injection to achieve remote…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Collection of Python and Bash scripts for penetration testing tasks including DNS enumeration, form scraping, shellcode generation, PowerShell…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

An evil RAT (Remote Administration Tool) for macOS / OS X.

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

An XSS exploitation command-line interface and payload generator.

Self contained htaccess shells and attacks