
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Notion as a platform for offensive operations

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

A third-party Gopher Assassin for the Havoc Framework.

ScareCrow - Payload creation framework designed around EDR bypass.

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries


Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Framework for generating shellcode and exploit payloads, designed for penetration testing and security research to automate payload creation and…

Atmail XSS-CSRF-RCE Exploit Chain

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.