Various webshells. We accept pull requests for additions to this collection.
☆1,023Oct 4, 2023Updated 2 years ago
Alternatives and similar repositories for webshells
Users that are interested in webshells are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Fetch, install and search exploit archives from exploit sites.☆118Oct 10, 2023Updated 2 years ago
- Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!☆1,946Mar 3, 2021Updated 5 years ago
- Impacket is a collection of Python classes for working with network protocols.☆15,807Updated this week
- WebShell Collect☆393Sep 14, 2016Updated 9 years ago
- Netcat for windows 32/64 bit☆795Apr 3, 2024Updated 2 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- The ultimate WinRM shell for hacking/pentesting☆5,395Jun 2, 2026Updated last week
- Webshell && Backdoor Collection☆2,003Apr 6, 2020Updated 6 years ago
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆19,991Jun 8, 2026Updated last week
- This is a webshell open source project☆10,736Dec 24, 2024Updated last year
- A swiss army knife for pentesting networks☆9,137Dec 6, 2023Updated 2 years ago
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆9,942Apr 25, 2024Updated 2 years ago
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.☆2,005Oct 10, 2018Updated 7 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,208May 11, 2023Updated 3 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆13,015Aug 17, 2020Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆4,872Jun 15, 2020Updated 5 years ago
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆7,932Sep 6, 2023Updated 2 years ago
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in …☆71,476Updated this week
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆6,480Updated this week
- Monitor linux processes without root permissions☆6,049Mar 1, 2026Updated 3 months ago
- Post Exploitation Collection☆1,580May 1, 2020Updated 6 years ago
- Six Degrees of Domain Admin☆10,553Mar 2, 2026Updated 3 months ago
- Weaponized web shell☆3,526Oct 1, 2025Updated 8 months ago
- PHP Webshell with handy features☆2,643Jul 6, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Linux privilege escalation auditing tool☆6,523Mar 20, 2026Updated 2 months ago
- A tool to abuse Exchange services☆2,305Jun 10, 2024Updated 2 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆2,789Dec 18, 2021Updated 4 years ago
- An ArchLinux based distribution for penetration testers and security researchers.☆3,397Updated this week
- Empire is a PowerShell and Python post-exploitation agent.☆7,841Jan 19, 2020Updated 6 years ago
- Wiki to collect Red Team infrastructure hardening resources☆4,488Oct 1, 2025Updated 8 months ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,929Nov 10, 2023Updated 2 years ago
- Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.☆5,553Apr 17, 2025Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,748Jan 5, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Fast web fuzzer written in Go☆16,214Apr 26, 2026Updated last month
- GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.☆13,336May 27, 2026Updated 2 weeks ago
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆78,303Jun 6, 2026Updated last week
- SMBMap is a handy SMB enumeration tool☆2,042Jan 6, 2026Updated 5 months ago
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆2,979Nov 19, 2025Updated 6 months ago
- JAWS - Just Another Windows (Enum) Script☆1,957Apr 19, 2021Updated 5 years ago
- Directory/File, DNS and VHost busting tool written in Go☆13,807Updated this week