
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

In-memory token vault BOF for Cobalt Strike

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

CLI tool for the Horizon3.ai API

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Extending of metasploit-framework

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

A modular distributed penetration testing tool.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Cobalt Strike HTTPS beaconing over Microsoft Graph API

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/



Python-Based Pentesting CLI Tool