
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Builds flashable installer ZIPs that deploy a mobile penetration-testing environment on Android, including kernel boot patching, rootfs integration,…

POC for CVE-2025-24054

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A BOF that runs unmanaged PEs inline

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

In-memory token vault BOF for Cobalt Strike

Remove API hooks from a Beacon process.

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Declarative penetration testing orchestration framework

Metasploit module for CVE-2018-4878

Kvasir: Penetration Test Data Management