
gitpwnd
GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service…

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A collection of AWS penetration testing junk

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.

Red Teaming & Pentesting checklists for various engagements

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

Post-exploitation tool for hiding processes from monitoring applications

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Simple (relatively) things allowing you to dig a bit deeper than usual.

Android Remote Access Trojan

Cobalt Strike extension for post-exploitation persistence using SharpStay .NET assembly. Provides GUI-driven persistence via Registry keys, Scheduled…