
raider
OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Exploit for CVE-2018-11776, a remote code execution vulnerability in Apache Struts via OGNL injection. Demonstrates the attack vector and impact for…

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Python SQL injection framework

A collaborative web exploitation framework.

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

A webshell framework for penetration testers.

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

Bypass firewall for traffic forwarding using webshell

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on