
BlueSAM
A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

POC for CVE-2025-24054

In-memory token vault BOF for Cobalt Strike

Remove API hooks from a Beacon process.

A BOF that runs unmanaged PEs inline

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Builds flashable installer ZIPs that deploy a mobile penetration-testing environment on Android, including kernel boot patching, rootfs integration,…

The Browser Exploitation Framework Project

Metasploit module for CVE-2018-4878

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Declarative penetration testing orchestration framework

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

Kvasir: Penetration Test Data Management