
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

An open-source post-exploitation framework for students, researchers and developers.

Attack and defend active directory using modern post exploitation adversary tradecraft activity

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

Cross-platform post-exploitation C2 server and agent in Go supporting HTTP/2, P2P, JA3 spoofing, .NET/PE execution, and shellcode injection for red…

📦 Make security testing of K8s, Docker, and Containerd easier.

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.