
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

Framework for generating shellcode and exploit payloads, designed for penetration testing and security research to automate payload creation and…

A third-party Gopher Assassin for the Havoc Framework.

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

ScareCrow - Payload creation framework designed around EDR bypass.

Notion as a platform for offensive operations

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Atmail XSS-CSRF-RCE Exploit Chain

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

A Ruby framework designed to aid in the penetration testing of WordPress systems.