

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from…

Open source C2 server created for stealth red team operations

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.

Automating Host Exploitation with AI

A Python package to interact with the Mitre ATT&CK Framework

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

Open-source collaborative platform for pentesters and red teams to manage projects, clients, vulnerabilities, and generate OWASP-compliant reports…

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…