
KITT
Python-Based Pentesting Framework

Python-Based Pentesting Framework

A collaborative web exploitation framework.

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

Open-source pentesting management and automation platform by Salesforce Product Security

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

Fully featured and community-driven hacking environment

Automated Tactics Techniques & Procedures

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

A simple bash based metasploit automation tool!


Advanced AI-Powered Exploitation Framework | CVE-2025-4664 & CVE-2025-2783 & CVE-2025-2857 & CVE-2025-30397 |

A little tool to play with Windows security

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

A True Instrumentable Binary Emulation Framework