
bantam
A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…


Automated Tool That Generates The Perfect Meterpreter Powershell Payload

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Automated All-in-One OS Command Injection Exploitation Tool

Local file inclusion exploitation tool

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Encoder to bypass WAF filters using XOR operations.

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

CVE-2025-55182 - Tool React2Shell

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)