
exploitgym
ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

A C2 post-exploitation framework

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

A third-party Gopher Assassin for the Havoc Framework.


CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level…