Log4Shell Exploit Kit (CVE-2021-44228)
Modular exploit for Log4j RCE. Includes malicious LDAP/HTTP server, payloads for multiple platforms, and WAF bypass.
Professional offensive security tools & exploit frameworks
Modular exploit for Log4j RCE. Includes malicious LDAP/HTTP server, payloads for multiple platforms, and WAF bypass.
Exploit for Spring Framework RCE via ClassLoader manipulation. Works on Spring MVC with JDK 9+ on Tomcat.
Complete exploitation chain for Microsoft Exchange: SSRF + Arbitrary File Write + RCE. CVE-2021-34473/34523/31207.
Collection of 5 recent Linux kernel privilege escalation exploits. DirtyPipe, GameOver(lay), StackRot, and more.
Python script that automates SQL injection to remote code execution escalation on MySQL, MSSQL, and PostgreSQL.
Advanced XSS payloads with cookie exfiltration, DOM keylogging, session hijacking, and in-page phishing.
Exploit for CVE-2021-34527 PrintNightmare. RCE and LPE via Windows Print Spooler service abuse.
Server-Side Template Injection payload generator for Jinja2, Twig, Freemarker, Velocity, Pebble, and Mako.
Automated script for WPA2 4-way handshake capture. Manages monitor mode, selective deauth, and captured handshake validation.
Module for creating Evil Twin Access Points with customizable captive portal. Captures WiFi credentials and web logins.
BLE scanner that enumerates devices, GATT services, characteristics, and allows value read/write. Ideal for IoT recon.
Passive monitor that detects deauthentication frames on the WiFi spectrum and alerts in real time. Defensive/awareness tool.