
hexstrike-ai
MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Open source C2 server created for stealth red team operations

MCP Server for Metasploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

A library for integrating communication channels with the Cobalt Strike External C2 server

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Model Context Protocol server for autonomous vulnerability discovery


PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Apfell C2 Server for the Google Chrome Extension Payload

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

CLI tool for the Horizon3.ai API