Various webshells. We accept pull requests for additions to this collection.
☆1,013Oct 4, 2023Updated 2 years ago
Alternatives and similar repositories for webshells
Users that are interested in webshells are comparing it to the libraries listed below
Sorting:
- Fetch, install and search exploit archives from exploit sites.☆118Oct 10, 2023Updated 2 years ago
- Common PHP webshells you might need for your Penetration Testing assignments or CTF challenges. Do not host the file(s) on your server!☆1,936Mar 3, 2021Updated 5 years ago
- Impacket is a collection of Python classes for working with network protocols.☆15,560Updated this week
- WebShell Collect☆394Sep 14, 2016Updated 9 years ago
- Netcat for windows 32/64 bit☆777Apr 3, 2024Updated last year
- Webshell && Backdoor Collection☆1,990Apr 6, 2020Updated 5 years ago
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆19,539Updated this week
- This is a webshell open source project☆10,701Dec 24, 2024Updated last year
- A swiss army knife for pentesting networks☆9,100Dec 6, 2023Updated 2 years ago
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆9,802Apr 25, 2024Updated last year
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.☆1,995Oct 10, 2018Updated 7 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,179May 11, 2023Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆12,912Aug 17, 2020Updated 5 years ago
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆4,846Jun 15, 2020Updated 5 years ago
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆7,860Sep 6, 2023Updated 2 years ago
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in …☆69,539Updated this week
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆6,383Jan 26, 2026Updated last month
- Monitor linux processes without root permissions☆5,927Mar 1, 2026Updated 3 weeks ago
- Post Exploitation Collection☆1,571May 1, 2020Updated 5 years ago
- Six Degrees of Domain Admin☆10,558Mar 2, 2026Updated 2 weeks ago
- Weaponized web shell☆3,499Oct 1, 2025Updated 5 months ago
- PHP Webshell with handy features☆2,608Jul 6, 2023Updated 2 years ago
- Linux privilege escalation auditing tool☆6,420Feb 19, 2026Updated last month
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆2,744Dec 18, 2021Updated 4 years ago
- A tool to abuse Exchange services☆2,302Jun 10, 2024Updated last year
- An ArchLinux based distribution for penetration testers and security researchers.☆3,276Updated this week
- Empire is a PowerShell and Python post-exploitation agent.☆7,828Jan 19, 2020Updated 6 years ago
- Wiki to collect Red Team infrastructure hardening resources☆4,458Oct 1, 2025Updated 5 months ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,851Nov 10, 2023Updated 2 years ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,660Jan 5, 2026Updated 2 months ago
- Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.☆5,518Apr 17, 2025Updated 11 months ago
- GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.☆12,816Mar 3, 2026Updated 2 weeks ago
- Fast web fuzzer written in Go☆15,750Apr 24, 2025Updated 10 months ago
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆76,106Updated this week
- SMBMap is a handy SMB enumeration tool☆2,026Jan 6, 2026Updated 2 months ago
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆2,924Nov 19, 2025Updated 4 months ago
- JAWS - Just Another Windows (Enum) Script☆1,930Apr 19, 2021Updated 4 years ago
- Directory/File, DNS and VHost busting tool written in Go☆13,532Updated this week
- MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, i…☆3,218Aug 7, 2025Updated 7 months ago