Skip to content

Entry

PhpSploit

Appears in 4 awesome lists

Full-featured C2 framework which silently persists on webserver via evil PHP oneliner. Built for stealth persistence, with many privilege-escalation & post-exploitation features.

Open github.comnil0x42/phpsploit

Found in these lists

Awesome Penetration Testing

Section: Web shells and C2 frameworks · Full-featured C2 framework which silently persists on webserver via evil PHP oneliner.

ActiveScore 83

Awesome Security

Section: Scanning / Pentesting · Full-featured C2 framework which silently persists on webserver via evil PHP oneliner. Built for stealth persistence, with many privilege-escalation & post-exploitation features.

SlowScore 70

Awesome Web Security

Section: Webshell · Full-featured C2 framework which silently persists on webserver via evil PHP oneliner by @nil0x42.

FreshScore 87

Awesome Hacking -An Amazing Project

Section: Tools · Full-featured C2 framework which silently persists on webserver via evil PHP oneliner

StaleScore 59

Recon-ng

Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.

In 6 listsDetails

Spyse

Spyse is an OSINT search engine that provides fresh data about the entire web. All the data is stored in its own DB for instant access and interconnected with each other for flexible search. Provided data: IPv4 hosts, sub/domains/whois, ports/banners/protocols, technologies, OS, AS, wide SSL/TLS…

In 5 listsDetails

beef

Command and control server for delivering exploits to commandeered Web browsers.

In 4 listsDetails

Ne0nd0g/merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

In 4 lists

Keyscope

Keyscope is an extensible key and secret validation for checking active secrets against multiple SaaS vendors built in Rust

In 4 lists

weevely3

Weaponized web shell by @epinna.

In 3 lists

SQLmap

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting…

In 3 lists

reverse-shell

Easy to remember reverse shell that should work on most Unix-like systems.

In 2 lists