
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

An open-source post-exploitation framework for students, researchers and developers.

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…


A simple C2 Framework written in modern C++

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Crystal Palace Evasion kit for Sliver

ABYSS C2 — HiSilicon DVR Exploit Framework (CVE-2020-25078). Educational IoT security research platform.

Post-exploitation framework that abuses trusted sites like Telegram and Discord for C2.

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Nimbo-C2 is yet another (simple and lightweight) C2 framework

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

poc for CVE-2025-24252 & CVE-2025-24132

CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…
