
nebula
AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Frieren is a micro-framework designed for use in routers and Single Board Computers (SBCs). This framework is built to be lightweight, efficient, and…

Adversary Emulation Framework

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

The Browser Exploitation Framework Project

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Bypass de autenticación por certificado en la VPN Remote-Access de Check Point (IKEv1).

Proof-of-concept exploit for CVE-2026-41089, a Netlogon remote code execution vulnerability in Windows Active Directory environments, for security…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…