
Langflow-cve-2026-33017-exploit
CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

iOS/macOS/Linux Remote Administration Tool

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Local & remote Windows DLL Proxying

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

MakeMeEnterpriseAdmin

A little tool to play with Windows security