Exploitation Tools

997 tools
breaking-telegram
breaking-telegram
Open Source Exploitation

Simple PoC script that allows you to exploit telegram's "send with timer" feature by saving any media sent with this functionality.

BRON
BRON
Open Source Exploitation

"Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber …

Browser-Data-Grabber
Browser-Data-Grabber
Free Exploitation

Stealer for Windows 10/11 for Chrome, Edge, Firefox, Brave with Wallet, Discord, Telegram and many more functions. Passwords, cookies, autof…

BrowserSnatch
BrowserSnatch
Open Source Exploitation

BrowserSnatch is a powerful browser stealer or browser data extraction tool intended to be used for ethical hacking or penetration testing.

brutas
brutas
Free Exploitation Password Attacks

Wordlists handcrafted (and automated) with ♥

brutespray
brutespray
Open Source Exploitation Password Attacks

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials a…

brutus
brutus
Open Source Exploitation Password Attacks

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alter…

Bug-Bounty-Beginner-Roadmap
Bug-Bounty-Beginner-Roadmap
Free Exploitation Reconnaissance

This repository is a curated resource for aspiring bug hunters, offering hands-on labs, tools, and structured guidance to support your learn…

bug-bounty-writeup
bug-bounty-writeup
Free Exploitation Web Application

This repo contains different variants of Bug Bounty & Security & Pentest & Tech related Articles

building-c2-implants-in-cpp
building-c2-implants-in-cpp
Open Source Exploitation

The source code files that accompany the short book "Building C2 Implants in C++: A Primer" by Steven Patterson (@shogun_lab).

bulwark
bulwark
Open Source Exploitation

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

BurnWP-Framework
BurnWP-Framework
Open Source Exploitation

BurnWP Advanced Exploiter System instead Scanner & Custom Plugin for Pentester

Burp-Suite-Certified-Practitioner-Exam-Study
Burp-Suite-Certified-Practitioner-Exam-Study
Free Exploitation Web Application

Burp Suite Certified Practitioner Exam Study

BurpAPISecuritySuite
BurpAPISecuritySuite
Open Source Exploitation Scanning & Enumeration

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration,…

BYOSI
BYOSI
Open Source Evasion Exploitation

Evade EDR's the simple way, by not touching any of the API's they hook.

BYOVD
BYOVD
Open Source Exploitation

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055,).

Bypass-Protection0x00
Bypass-Protection0x00
Free Evasion Exploitation

EDR & AV Bypass Arsenal— a comprehensive collection of tools, patches, and techniques for evading modern EDR and antivirus defenses.

bypass-url-parser
bypass-url-parser
Open Source Exploitation

Tool that tests MANY url bypasses to reach a 40X protected page.

Bypass-WAF-SQLMAP
Bypass-WAF-SQLMAP
Free Exploitation

Bypass WAF SQL Injection SQLMAP

BypassAV
BypassAV
Free Exploitation

This map lists the essential techniques to bypass anti-virus and EDR

ByteCaster
ByteCaster
Free Evasion Exploitation

Swiss Army Knife for payload encryption, obfuscation, and conversion to byte arrays – all in a single command (14 output formats supported)!…

byvalver
byvalver
Free Exploitation Forensics

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

C-hacks
C-hacks
Open Source Exploitation Reconnaissance

All social Media hacking with information gathering

cache-commander
cache-commander
Open Source Exploitation Scanning & Enumeration

Cache Commander — a TUI and MCP server to explore, audit, and clean developer cache directories. Scan for CVEs, find outdated packages, recl…