
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Adversary Emulation Framework


A collaborative web exploitation framework.

CVE-2026-8452 PreAuth RCE

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Windows User-Mode Shellcode Development Framework (WUMSDF)

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Crystal Palace Evasion kit for Sliver

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

A tool for generating reverse shell payloads on the fly.

Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via SolarWinds Dameware MRC smart card authentication bypass.

MCP Server for Metasploit

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…