
CDK
📦 Make security testing of K8s, Docker, and Containerd easier.

📦 Make security testing of K8s, Docker, and Containerd easier.

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A collaborative, multi-platform, red teaming framework

Undetectable Windows Payload Generation

A tool to transform Chromium browsers into a C2 Implant

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Nimbo-C2 is yet another (simple and lightweight) C2 framework

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Linux Persistence Detection, Hunting and Artifact Collection script

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…