
React2Shell
R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

The Browser Exploitation Framework Project

Builds flashable installer ZIPs that deploy a mobile penetration-testing environment on Android, including kernel boot patching, rootfs integration,…

A BOF that runs unmanaged PEs inline

In-memory token vault BOF for Cobalt Strike

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Kvasir: Penetration Test Data Management

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Remove API hooks from a Beacon process.

Metasploit module for CVE-2018-4878

Declarative penetration testing orchestration framework

POC for CVE-2025-24054

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.