A curated collection of offensive security tools, exploits, and scripts for penetration testing and security research.
Tools for web application security testing and bug hunting:
webEnum.sh- Web enumeration automation scriptxssAI.sh- AI-assisted XSS detection and exploitation
Proof-of-concept exploits for known vulnerabilities (check readme in the folder).
Various reverse shell implementations:
- ASP/ASPX -
asp_rev_shell.aspx,cmd-asp-5.1.asp,cmdasp.asp,cmdasp.aspx - PowerShell -
Invoke-ConPtyShell.ps1,Invoke-PowerShellTcp.ps1,powercat.ps1 - PHP -
php-reverse-shell.php,simple-backdoor.PHP - WordPress -
rev-shell-wp-plugin.zip
commands- Useful command referencesenum- Enumeration scripts and toolsturbo_intruder.py- High-speed HTTP request fuzzercheck_disabled_functions.php- PHP function restrictions checkerdotfiles.sh- Environment setup script
Remember: With great power comes great responsibility. Hack ethically. 🛡️