
Cerberus-React2Shell-Scanner-Exploit
Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting


MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Open source C2 server created for stealth red team operations

MCP Server for Metasploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

A library for integrating communication channels with the Cobalt Strike External C2 server

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Model Context Protocol server for autonomous vulnerability discovery

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Apfell C2 Server for the Google Chrome Extension Payload

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…