
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

In-memory token vault BOF for Cobalt Strike

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

CLI tool for the Horizon3.ai API

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Extending of metasploit-framework

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

A modular distributed penetration testing tool.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

A little tool to play with Windows security

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Cobalt Strike HTTPS beaconing over Microsoft Graph API

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…


Python-Based Pentesting CLI Tool