Various webshells. We accept pull requests for additions to this collection.
☆1,020Oct 4, 2023Updated 2 years ago
Alternatives and similar repositories for webshells
Users that are interested in webshells are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Fetch, install and search exploit archives from exploit sites.☆118Oct 10, 2023Updated 2 years ago
- Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!☆1,942Mar 3, 2021Updated 5 years ago
- Impacket is a collection of Python classes for working with network protocols.☆15,671Updated this week
- WebShell Collect☆394Sep 14, 2016Updated 9 years ago
- Netcat for windows 32/64 bit☆783Apr 3, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- The ultimate WinRM shell for hacking/pentesting☆5,358Mar 10, 2026Updated last month
- Webshell && Backdoor Collection☆2,000Apr 6, 2020Updated 6 years ago
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆19,768Updated this week
- This is a webshell open source project☆10,722Dec 24, 2024Updated last year
- A swiss army knife for pentesting networks☆9,129Dec 6, 2023Updated 2 years ago
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆9,878Apr 25, 2024Updated 2 years ago
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.☆1,999Oct 10, 2018Updated 7 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,193May 11, 2023Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆12,967Aug 17, 2020Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆4,859Jun 15, 2020Updated 5 years ago
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆7,905Sep 6, 2023Updated 2 years ago
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in …☆70,522Updated this week
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆6,433Jan 26, 2026Updated 3 months ago
- Monitor linux processes without root permissions☆5,983Mar 1, 2026Updated 2 months ago
- Post Exploitation Collection☆1,573May 1, 2020Updated 6 years ago
- Six Degrees of Domain Admin☆10,532Mar 2, 2026Updated 2 months ago
- Weaponized web shell☆3,511Oct 1, 2025Updated 7 months ago
- PHP Webshell with handy features☆2,628Jul 6, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Linux privilege escalation auditing tool☆6,470Mar 20, 2026Updated last month
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆2,763Dec 18, 2021Updated 4 years ago
- A tool to abuse Exchange services☆2,302Jun 10, 2024Updated last year
- An ArchLinux based distribution for penetration testers and security researchers.☆3,336Updated this week
- Empire is a PowerShell and Python post-exploitation agent.☆7,831Jan 19, 2020Updated 6 years ago
- Wiki to collect Red Team infrastructure hardening resources☆4,474Oct 1, 2025Updated 7 months ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,886Nov 10, 2023Updated 2 years ago
- Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.☆5,533Apr 17, 2025Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,700Jan 5, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Fast web fuzzer written in Go☆15,957Updated this week
- GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.☆13,131Apr 20, 2026Updated last week
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆77,264Apr 22, 2026Updated last week
- SMBMap is a handy SMB enumeration tool☆2,037Jan 6, 2026Updated 3 months ago
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆2,951Nov 19, 2025Updated 5 months ago
- JAWS - Just Another Windows (Enum) Script☆1,942Apr 19, 2021Updated 5 years ago
- Directory/File, DNS and VHost busting tool written in Go☆13,654Updated this week