
gopacket
A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

RFI to RCE Nagios/NagiosXI exploitation

Go-based exploit for CVE-2023-38646 in Metabase, enabling remote code execution and reverse shell connection to an attacker-controlled host.

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

C# port of WMImplant which uses either CIM or WMI to query remote systems

CVE-2017-17215 HuaWei Router RCE (NOT TESTED)

Exploit for CVE-2022-46169, an unauthenticated remote code execution in Cacti 1.2.22, delivering a reverse shell to a specified host and port.

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Single executable reverse SOCKS5 proxy written in Golang.

A third-party Gopher Assassin for the Havoc Framework.

Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528

Hershell is a simple TCP reverse shell written in Go.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

A script written lazily for generating cross-platform backdoors on the go :)

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.

Proof-of-concept exploit for CVE-2024-23897 enabling remote code execution on Jenkins instances via vulnerable args4j command-line parser. Written in…