
Aggressor-Aggregator
A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.
A cross platform C2/post-exploitation framework.

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege


The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

Plugin For BurpSuite (Pentester)

Specify targets and run sets of tools against them

CLI tool for the Horizon3.ai API

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)


Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

A free and open source command-line shell and scripting language designed especially for security testing