
C3
Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Adversary Emulation Framework

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

A framework for constructing self-spreading binaries

Collection of exploits targeting OSGi Java framework versions 3.1.1–3.20 for penetration testing and vulnerability exploitation.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Python and Powershell internal penetration testing framework

Deploys realistic virtual SCADA/ICS testbeds with IEC 60870-5-104 and OPC-UA nodes, enabling attack simulations, legitimate packet generation, and…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…