
T3MP3ST
autonomous red teaming platform; multi-agent offensive-security meta-harness

autonomous red teaming platform; multi-agent offensive-security meta-harness

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

User-Agent , X-Forwarded-For and Referer SQLI Fuzzer


Exploit for the vulnerability CVE-2024-43044 in Jenkins

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

基于MemShellParty的Agent内存马二开,使其兼容主流操作系统,适用于在无回显命令执行场景下实现打入内存马。

CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Weblogic Unrestricted File Upload

Pentest TeamCity using Metasploit