
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

The ultimate WinRM shell for hacking/pentesting

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.

Lightweight Go-based reverse shell management server with a web GUI for interactive shell sessions, session management, and multi-tab terminal…

Go-based WinRM client for remote command execution and lateral movement on Windows systems during penetration tests.

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised…

JSshell - JavaScript reverse/remote shell

Yet Another PHP Shell - The most complete PHP reverse shell

C2/post-exploitation framework

PHP 8.1.0-dev Backdoor System Shell Script

A Netcat-style backdoor for pentesting and pentest exercises

Hacking Artifactory with server side template injection

RAT / Botnet Simulator for pentest / education

Hershell is a simple TCP reverse shell written in Go.

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell…

My python3 implementation of a Forward Shell