ENNAENNA
💥

Exploitation

22 tools indexed

Exploitation frameworks, payload generators, post-exploitation tools, and privilege escalation utilities. These tools are used in penetration testing and red team operations to demonstrate the real-world impact of discovered vulnerabilities.

Metasploit Framework

Ruby
Featured

The world's most used penetration testing framework. Exploit development, payload delivery, post-exploitation.

exploitpayloadpost-exploitationclassic
38.0k14.8k24d ago

BloodHound

Go
Featured

Active Directory attack path mapping. Visualizes privilege escalation paths using graph theory.

active-directorygraphprivilege-escalationattack-path
3.0k31423d ago

Impacket

Python

Collection of Python classes for working with network protocols. Essential for Windows/AD pentesting.

smbactive-directoryprotocolwindows
15.7k3.9k23d ago

CrackMapExec

Python
Featured

Swiss army knife for pentesting Active Directory. SMB, LDAP, MSSQL, WinRM enumeration and exploitation.

active-directorysmblateral-movementcredential-spraying
9.1k1.7k2y ago

Evil-WinRM

Ruby

Ultimate WinRM shell for pentesting. Upload/download, in-memory PowerShell, DLL injection, pass-the-hash.

winrmpowershellpass-the-hashpost-exploitation
5.4k6792mo ago

Covenant

C#

.NET C2 framework. Collaborative, web-based interface for red team operations and implant management.

c2red-teamdotnetimplant
4.7k8251y ago

Sliver

Go
Featured

Open-source C2 framework by BishopFox. mTLS, HTTP(S), DNS, WireGuard implants with multi-operator support.

c2red-teammulti-operatorimplant
11.1k1.5k29d ago

Ligolo-ng

Go

Advanced tunneling/pivoting tool. Creates a TUN interface for transparent proxying through compromised hosts.

tunnelingpivotingtunproxy
4.5k4263mo ago

Chisel

Go

Fast TCP/UDP tunnel over HTTP secured via SSH. Single binary, works behind firewalls and NAT.

tunnelingfirewall-bypasssshsingle-binary
15.9k1.6k1mo ago

LinPEAS

Shell
Featured

Linux privilege escalation enumeration script. Finds misconfigs, SUID bins, creds, and escalation paths.

privescenumerationlinuxsuid
19.7k3.4k28d ago

pspy

Go

Monitor Linux processes without root. Detects cron jobs, user commands, and process events in real time.

process-monitorcronno-rootenumeration
6.0k5672mo ago

TheFatRat

Shell

Exploit and payload generator. Creates backdoors with msfvenom, compiles with anti-AV evasion techniques.

payloadbackdoormsfvenomevasion
11.2k2.5k2y ago

SearchSploit

Shell

Command-line tool for searching Exploit-DB - find public exploits and shellcode for known vulnerabilities offline.

exploit-databasecveshellcodevulnerability-research
7.9k1.9k3y ago

pwntools

Python

CTF framework and exploit development library for rapid prototyping of binary exploitation and reverse engineering.

ctfbinary-exploitationropshellcode
13.4k1.8k23d ago

Ropper

Python

Display and search for ROP/JOP/SOP gadgets in binaries to assist with exploit development and bypass mitigations.

rop-gadgetsexploit-developmentbinary-analysismitigation-bypass
2.1k2221y ago

RouterSploit

Python

Open-source exploitation framework for embedded devices and routers.

routeriotexploitationembedded
13.1k2.4k2mo ago

ROPgadget

Python

Search ROP gadgets in binaries for chain-building across ELF, PE, and Mach-O.

ropexploitationbinarygadget
4.4k5755mo ago

one_gadget

Ruby

Find one-gadget RCE execve calls in libc for streamlined exploit development.

exploitlibcgadgetrce
2.3k14829d ago

RsaCtfTool

Python

RSA multi-attack tool for recovering private keys from weak public keys.

rsacryptoctfattack
6.9k99729d ago

git-dumper

Python

Dumps exposed .git repositories from web servers, reconstructing the full source code and commit history.

git-exposuresource-codeweb-exploitationinformation-disclosure
2.5k2962mo ago

CAPEv2

Python

Malware behavior analysis sandbox. Detonates samples and extracts configs, payloads, network IOCs, and API call traces.

malware-sandboxbehavioral-analysisconfig-extractionautomated-analysis
3.2k56223d ago

DllShimmer

Go

Weaponizes DLL hijacking by generating proxy DLLs with matching export address tables and C++ backdoor boilerplate.

dll-hijackingproxy-dllpersistenceevasion
741951mo ago