# Made with Payload CMS — full catalog > A curated, daily-updated gallery of the best open-source projects built with Payload CMS, ranked by GitHub stars. Discover dashboards, UI kits, e-commerce, blogs and dev tools. ## About - Gallery: https://madewithwhat.net/payload/ - Curated summary: https://madewithwhat.net/payload/llms.txt - Projects indexed: 359 - Data source: GitHub (refreshed daily) - Last scraped: 2026-07-22T09:29:07.587227+00:00 ## DevTools (261) - [payloads](https://madewithwhat.net/payload/project/payloads/): Git All the Payloads! A collection of web attack payloads. (3,966 stars, GPL-3.0) - [Stitch](https://madewithwhat.net/payload/project/stitch/): Python Remote Administration Tool (RAT) (3,626 stars) - [TegraRcmGUI](https://madewithwhat.net/payload/project/tegrarcmgui/): C++ GUI for TegraRcmSmash (Fusée Gelée exploit for Nintendo Switch) (2,273 stars, GPL-2.0) - [Medusa](https://madewithwhat.net/payload/project/medusa/): Medusa,XSS、、CVE、、DNSLOG、、, (2,240 stars, GPL-3.0) - [java-memshell-generator](https://madewithwhat.net/payload/project/java-memshell-generator/): Java |A customizable Java in-memory webshell generation tool. (2,219 stars, MIT) - [java-chains](https://madewithwhat.net/payload/project/java-chains/): Java Vulnerability Exploitation Platform (2,121 stars) - [Attiny85](https://madewithwhat.net/payload/project/attiny85/): RubberDucky like payloads for DigiSpark Attiny85 (1,625 stars, LGPL-3.0) - [Chimera](https://madewithwhat.net/payload/project/chimera/): Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions. (1,586 stars) - [MemShellParty](https://madewithwhat.net/payload/project/memshellparty/): Java Web ,, (1,549 stars, MIT) - [Burp-Suite-Certified-Practitioner-Exam-Study](https://madewithwhat.net/payload/project/burp-suite-certified-practitioner-exam-study/): Burp Suite Certified Practitioner Exam Study (1,440 stars) - [amber](https://madewithwhat.net/payload/project/amber/): Reflective PE packer. (1,428 stars, MIT) - [msfpc](https://madewithwhat.net/payload/project/msfpc/): MSFvenom Payload Creator (MSFPC) (1,329 stars, MIT) - [evilgrade](https://madewithwhat.net/payload/project/evilgrade/): Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates. (1,329 stars) - [Brutal](https://madewithwhat.net/payload/project/brutal/): Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy. Brutal is a toolkit to quickly create various payload,powershell attack, virus attack and launch listener for a Human Interface Device ( Payload Teensy ) (1,264 stars, GPL-3.0) - [athena](https://madewithwhat.net/payload/project/athena/): Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool! (1,247 stars, MIT) - [CVE-2021-44228-PoC-log4j-bypass-words](https://madewithwhat.net/payload/project/cve-2021-44228-poc-log4j-bypass-words/): CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks (950 stars) - [AppSec-Payloads](https://madewithwhat.net/payload/project/appsec-payloads/): AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters (940 stars, MIT) - [wordlists](https://madewithwhat.net/payload/project/wordlists/): Infosec Wordlists and more. (938 stars) - [Apkmod](https://madewithwhat.net/payload/project/apkmod/): Apkmod can decompile, recompile, sign APK, and bind the payload with any legit APP (818 stars, GPL-3.0) - [TOP](https://madewithwhat.net/payload/project/top/): TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things (732 stars) - [hackingtoolkit](https://madewithwhat.net/payload/project/hackingtoolkit/): ALL IN ONE Hacking Tool For Hackers, Penetration Tester and Cybersecurity. New Version Beginner to Advanced Tool. This Tool is made for educational purpose only! Author will not be responsible for any misuse of this toolkit! (728 stars, MIT) - [hackers-tool-kit](https://madewithwhat.net/payload/project/hackers-tool-kit/): Its a framework filled with alot of options and hacking tools you use directly in the script from brute forcing to payload making im still adding more stuff i now have another tool out called htkl-lite its hackers-tool-kit just not as big and messy to see updates check on my instagram @tuf_unkn0wn or if there are any problems message me on instagram (582 stars, Apache-2.0) - [Payload-SDK](https://madewithwhat.net/payload/project/payload-sdk/): DJI Payload SDK Official Repository (519 stars) - [malware-jail](https://madewithwhat.net/payload/project/malware-jail/): Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction. Written for Node.js (476 stars, MIT) - [backdoorppt](https://madewithwhat.net/payload/project/backdoorppt/): transform your payload.exe into one fake word doc (.ppt) (468 stars) - [Paybag](https://madewithwhat.net/payload/project/paybag/): Simple and easy Metasploit payload generator for Linux & Termux (464 stars, MIT) - [java-echo-generator](https://madewithwhat.net/payload/project/java-echo-generator/): Java |A customizable Java echo payload generation tool. (464 stars, MIT) - [PELoader](https://madewithwhat.net/payload/project/peloader/): PE loader with various shellcode injection techniques (454 stars) - [Payloader](https://madewithwhat.net/payload/project/payloader/): Payload | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript (442 stars, AGPL-3.0) - [gray_hat_csharp_code](https://madewithwhat.net/payload/project/gray-hat-csharp-code/): This repository contains full code examples from the book Gray Hat C# (397 stars, BSD-3-Clause) - [AiScan-N](https://madewithwhat.net/payload/project/aiscan-n/): AiScan-N !Ai(),、、、、,Ai【CLI Agent】 ,Ai,(),,(),! :(、CTF、Web、、、、APT、)():https://mp.weixin.qq.com/s/7lsUdbrxkDy4P5pZhEWv7Q (397 stars) - [ImgBackdoor](https://madewithwhat.net/payload/project/imgbackdoor/): Hide your payload into.jpg file (395 stars, Apache-2.0) - [nosqlinjection_wordlists](https://madewithwhat.net/payload/project/nosqlinjection-wordlists/): This repository contains payload to test NoSQL Injections (380 stars, MIT) - [BadUSB-Payloads](https://madewithwhat.net/payload/project/badusb-payloads/): Repository for Flipper Zero/USB Rubber Ducky payloads (351 stars) - [CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera](https://madewithwhat.net/payload/project/cve-2022-0337-poc-google-chrome-microsoft-edge-opera/): [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337 (340 stars) - [HatSploit](https://madewithwhat.net/payload/project/hatsploit/): Modular penetration testing platform that enables you to write, test, and execute exploit code. (328 stars, MIT) - [payload-visual-editor](https://madewithwhat.net/payload/project/payload-visual-editor/): Payload CMS plugin which provides a visual live editor directly in the Admin UI. Works for collections and globals. Compatible with any kind of JS/TS based frontend technology. (301 stars, MIT) - [badchars](https://madewithwhat.net/payload/project/badchars/): Bad char generator to instruct encoders such as shikata-ga-nai to transform those to other chars. (294 stars, MIT) - [payload-better-fields-plugin](https://madewithwhat.net/payload/project/payload-better-fields-plugin/): This plugin aims to provide you with very specific and improved fields for the Payload admin panel. (290 stars, MIT) - [Shellcode-Loader](https://madewithwhat.net/payload/project/shellcode-loader/): Open repository for learning dynamic shellcode loading (sample in many programming languages) (288 stars) - [Armor](https://madewithwhat.net/payload/project/armor/): Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners. (278 stars) - [RATel](https://madewithwhat.net/payload/project/ratel/): RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server sends commands and the client executes the commands and sends the result back to the server. The client is completely undetectable by anti-virus software. (277 stars, MIT) - [pakkero](https://madewithwhat.net/payload/project/pakkero/): Pakkero is a binary packer written in Go made for fun and educational purpose. Its main goal is to take in input a program file (elf binary, script, even appimage) and compress it, protect it from tampering and intrusion. (276 stars, GPL-3.0) - [CobaltStrike_OpenBeacon](https://madewithwhat.net/payload/project/cobaltstrike-openbeacon/): Fully functional, from-scratch alternative to the Cobalt Strike Beacon (red teaming tool), offering transparency and flexibility for security professionals and enthusiasts. (270 stars, MIT) - [gear](https://madewithwhat.net/payload/project/gear/): Web3 Ultimate Execution Engine (264 stars, GPL-3.0) - [SPYBOMB](https://madewithwhat.net/payload/project/spybomb/): SPY BOMB is a tool used to generate various payloads for android,windows,ios,mac and many more it is very user friendly tool. (261 stars) - [Payload-Download-Cradles](https://madewithwhat.net/payload/project/payload-download-cradles/): This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections. (258 stars) - [athena-nix](https://madewithwhat.net/payload/project/athena-nix/): Athena OS Nix configuration files focused on Cybersecurity. Learn, practice and enjoy with any hacking tool! (252 stars, MIT) - [CamRaptor](https://madewithwhat.net/payload/project/camraptor/): CamRaptor is a tool that exploits several vulnerabilities in popular DVR cameras to obtain network camera credentials. (247 stars, MIT) - [pencode](https://madewithwhat.net/payload/project/pencode/): Complex payload encoder (244 stars, MIT) - [SNOWCRASH](https://madewithwhat.net/payload/project/snowcrash/): A polyglot payload generator (243 stars, MIT) - [Duckyspark](https://madewithwhat.net/payload/project/duckyspark/): Translator from USB-Rubber-Ducky payloads to a Digispark code. (232 stars, MIT) - [BadUSB_passStealer](https://madewithwhat.net/payload/project/badusb-passstealer/): This script allows you to steal some informations from a computer. (226 stars, MIT) - [BetterXencrypt](https://madewithwhat.net/payload/project/betterxencrypt/): A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs. (225 stars, GPL-3.0) - [wafpass](https://madewithwhat.net/payload/project/wafpass/): Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF. (222 stars, MIT) - [hiphp](https://madewithwhat.net/payload/project/hiphp/): The BackDoor of HIPHP gives you the power to control websites based on PHP using HTTP/HTTPS protocol. By sending files, tokens and commands through port 80's POST/GET method, users can access a range of activities such as downloading and editing files. It also allows for connecting to Tor networks with password protection for extra security. (219 stars, MIT) - [payload-plugin-lexical](https://madewithwhat.net/payload/project/payload-plugin-lexical/): Extends payload CMS with Meta's lexical RichText editor - a much more advanced and customizable richtext editor (209 stars, MIT) - [Venoma](https://madewithwhat.net/payload/project/venoma/): Yet another C++ Cobalt Strike beacon dropper with Compile-Time API hashing and custom indirect syscalls execution (201 stars) - [payload-tools](https://madewithwhat.net/payload/project/payload-tools/): This repository contains a set of powerful plugins designed to enhance your Payload CMS projects. Whether you're managing complex content structures or optimizing the authoring experience, these plugins will help streamline your workflow. (180 stars, Apache-2.0) - [CVE-2021-21123-PoC-Google-Chrome](https://madewithwhat.net/payload/project/cve-2021-21123-poc-google-chrome/): Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more... (175 stars) - [CVE-Master](https://madewithwhat.net/payload/project/cve-master/): CVE、POC、CNVD++FUZZ,,. (174 stars, MIT) - [BadUSB_keyloggerInjector](https://madewithwhat.net/payload/project/badusb-keyloggerinjector/): This script allows you to inject an invisible keylogger thanks to a Bad USB. (163 stars, MIT) - [payload-totp](https://madewithwhat.net/payload/project/payload-totp/): Add an extra security layer to PayloadCMS using a Time-based One-time Password (TOTP). (153 stars) - [relayer](https://madewithwhat.net/payload/project/relayer/): SMB Relay Attack Script (146 stars, GPL-3.0) - [codasm](https://madewithwhat.net/payload/project/codasm/): Payload encoding utility to effectively lower payload entropy. (130 stars, MIT) - [NET-MalwareCryptor](https://madewithwhat.net/payload/project/net-malwarecryptor/): Legacy OpenSource malware packer for.NET Framework executable files (130 stars, MIT) - [htk-lite](https://madewithwhat.net/payload/project/htk-lite/): htk-lite is a lighter version of hackers-tool-kit but it still has the same hacking ability as hackers-tool-kit (127 stars, Apache-2.0) - [MalQR.github.io](https://madewithwhat.net/payload/project/malqr-github-io/): MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners. (127 stars, GPL-3.0) - [Cobalt-Strike-Ultimate-Arsenal](https://madewithwhat.net/payload/project/cobalt-strike-ultimate-arsenal/): Cobalt Strike module x loader x profile x wike / A public collection of open resources for Cobalt Strike (only legal use in Red Team and penetration testing (125 stars) - [SQL_Injection_Payload](https://madewithwhat.net/payload/project/sql-injection-payload/): SQL Injection Payload List (121 stars, MIT) - [WHID_Toolkit](https://madewithwhat.net/payload/project/whid-toolkit/): Simple script for the WHID injector - a rubberducky wifi (120 stars) - [xeca](https://madewithwhat.net/payload/project/xeca/): PowerShell payload generator (120 stars, GPL-3.0) - [web-cfw-loader](https://madewithwhat.net/payload/project/web-cfw-loader/): A payload launcher made in javascript for the Nintendo Switch (116 stars, MIT) - [go-deliver](https://madewithwhat.net/payload/project/go-deliver/): Go-deliver is a payload delivery tool coded in Go. (114 stars, Apache-2.0) - [payload-plugin-oauth](https://madewithwhat.net/payload/project/payload-plugin-oauth/): Add oAuth sign in to your Payload CMS site (113 stars, MIT) - [payload-bites](https://madewithwhat.net/payload/project/payload-bites/): Collection of various bite-sized Payload v3 plugins and tools (112 stars, MIT) - [DUCKSPLOIT](https://madewithwhat.net/payload/project/ducksploit/): Windows Hacking FrameWork using Reverse Shell (111 stars) - [tar-split](https://madewithwhat.net/payload/project/tar-split/): checksum-reproducible tar archives (utility/library) (110 stars, BSD-3-Clause) - [CVE-2024-6387](https://madewithwhat.net/payload/project/cve-2024-6387/): PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit) (110 stars) - [CyberEye](https://madewithwhat.net/payload/project/cybereye/): Modded Program for remote control of windows computers via telegram bot. Written in C# (109 stars, LGPL-3.0) - [payload-lexical-typography](https://madewithwhat.net/payload/project/payload-lexical-typography/): Payload plugin for extending lexical typography options (Text color, Font size, Letter spacing, Line height, Font Family) (108 stars, MIT) - [DotNET_XorCryptor](https://madewithwhat.net/payload/project/dotnet-xorcryptor/): A new simple and powerfull packer for malware (106 stars, MIT) - [Shortcut-Payload-Generator](https://madewithwhat.net/payload/project/shortcut-payload-generator/): AutoIt HackTool, Shortcuts.lnk Payloads Generator As LNK-KISSER. (103 stars) - [payload-plugins](https://madewithwhat.net/payload/project/payload-plugins/): A collection of powerful plugins designed to enhance Payload CMS (99 stars) - [window-rat](https://madewithwhat.net/payload/project/window-rat/): The purpose of this tool is to test the window10 defender protection and also other antivirus protection. (95 stars, MIT) - [payload-blurhash-plugin](https://madewithwhat.net/payload/project/payload-blurhash-plugin/): Payload CMS plugin for automatic Blurhash encoding of images (95 stars, Unlicense) - [dbcrust](https://madewithwhat.net/payload/project/dbcrust/): Fast psql-style database CLI/workbench for PostgreSQL, MySQL, SQLite, ClickHouse, MongoDB, Elasticsearch, and SQL over Parquet/CSV/JSON — with optional AI, SSH/Vault, Python & Django. (90 stars, MIT) - [Taskschedule-Persistence-Download-Cradles](https://madewithwhat.net/payload/project/taskschedule-persistence-download-cradles/): Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged (89 stars) - [httpworker](https://madewithwhat.net/payload/project/httpworker/): A Flask-based HTTP(S) command and control (C2) framework with a web interface. Custom Windows EXE/DLL implants written in C++. For educational use only. (89 stars) - [sexettintool](https://madewithwhat.net/payload/project/sexettintool/): İçerisinde 100'den fazla modül ve özelliği barındıran çok amaçlı bir siber güvenlik aracı. (87 stars, AGPL-3.0) - [payload-webp](https://madewithwhat.net/payload/project/payload-webp/): payloadcms/payload plugin for automatic image conversion to webp format. (85 stars, GPL-3.0) - [Path_Travelsal_Payload_List](https://madewithwhat.net/payload/project/path-travelsal-payload-list/): Path Traversal Vulnerability Payload List (83 stars, MIT) - [flipperducky-badUSB-payload-generator](https://madewithwhat.net/payload/project/flipperducky-badusb-payload-generator/): GUI (Graphic user interface) in HTML, CSS, JavaScript, to make easyer and faster to create payload (.txt) for you Flipper Zero's bad-USB function. (82 stars, MIT) - [payload-plugins](https://madewithwhat.net/payload/project/payload-plugins/): A collection of Payload plugins made by OVERSIGHT. (81 stars, MIT) - [Venomsploit](https://madewithwhat.net/payload/project/venomsploit/): Meterpreter payload for all platforms (79 stars, MIT) - [Fairplay](https://madewithwhat.net/payload/project/fairplay/): Artifact monitoring that ensures fairplay (78 stars, GPL-3.0) - [payload-cloudinary-plugin](https://madewithwhat.net/payload/project/payload-cloudinary-plugin/): Upload media to Cloudinary service (77 stars, MIT) - [otaripper](https://madewithwhat.net/payload/project/otaripper/): Fast, safe, and reliable Android OTA partition extractor (77 stars, Apache-2.0) - [payloadcms-lexical-ext](https://madewithwhat.net/payload/project/payloadcms-lexical-ext/): Extended lexical editor features for Payload CMS (Text color, highlight, block background, embeds) (73 stars, MIT) - [payload-better-editor](https://madewithwhat.net/payload/project/payload-better-editor/): Block editor plugin for Payload CMS that adds a side-by-side live-preview iframe and sidebar to the edit view. (72 stars, MIT) - [Shells](https://madewithwhat.net/payload/project/shells/): List of payloads: reverse shell, bind shell, webshell. (72 stars) - [payload-auditor](https://madewithwhat.net/payload/project/payload-auditor/): Payload CMS plugin for event tracking, auditing, and security. Monitor activities and analyze user behavior. (70 stars, MIT) - [payload-s3-upload](https://madewithwhat.net/payload/project/payload-s3-upload/): Send Payload CMS uploads to Amazon S3 (70 stars, MIT) - [ATMSFE](https://madewithwhat.net/payload/project/atmsfe/): Termux Auto-Metasploit (69 stars, GPL-3.0) - [WinRAT](https://madewithwhat.net/payload/project/winrat/): (Windows/Linux/Mac) Remote Administration Tool (69 stars, MIT) - [Csharp-Loader](https://madewithwhat.net/payload/project/csharp-loader/): Download a.NET payload and run it on memory (67 stars, Apache-2.0) - [LimeLogger](https://madewithwhat.net/payload/project/limelogger/): Simple C# Keylogger (Keyboard Layout) (65 stars, MIT) - [MalwareShell](https://madewithwhat.net/payload/project/malwareshell/): Create a powershell malware loader to run C#.cs code on runtime (65 stars) - [TTWAF](https://madewithwhat.net/payload/project/ttwaf/): 「」Test a list of payloads and see if you can bypass it (64 stars, GPL-3.0) - [payload-auth0-plugin](https://madewithwhat.net/payload/project/payload-auth0-plugin/): Extends payloadcms with Auth0 integration (62 stars, MIT) - [payload-redis-cache](https://madewithwhat.net/payload/project/payload-redis-cache/): A Redis cache plugin for Payload CMS (61 stars, MIT) - [Avenge](https://madewithwhat.net/payload/project/avenge/): A project worth exploring. (61 stars) - [OS_Command_Payload_List](https://madewithwhat.net/payload/project/os-command-payload-list/): OS Command Injection Vulnerability Payload List (58 stars, MIT) - [purelove](https://madewithwhat.net/payload/project/purelove/): Purelove is a lightweight penetration testing framework, in order to better security testers testing holes with use. (58 stars) - [payload-plugin-pagespeed](https://madewithwhat.net/payload/project/payload-plugin-pagespeed/): A Payload CMS plugin that integrates PageSpeed Insights into your project. (56 stars, MIT) - [BadUSB_reverseShellInjector](https://madewithwhat.net/payload/project/badusb-reverseshellinjector/): This script allows you to take control of a PC with a reverseShell attack. (56 stars, MIT) - [WHID-Payloads](https://madewithwhat.net/payload/project/whid-payloads/): A collection of Payloads for the WHID Cactus (55 stars) - [mc-webui](https://madewithwhat.net/payload/project/mc-webui/): Meshcore web client (54 stars, MIT) - [PSImage-Delivery](https://madewithwhat.net/payload/project/psimage-delivery/): Use Invoke-PSImage to deliver a payload in an Image (53 stars) - [PandaCrypter](https://madewithwhat.net/payload/project/pandacrypter/): PandaCrypter is a C#-based tool designed to convert PowerShell scripts into obfuscated batch files (.bat) with encryption and additional features for execution control. (52 stars, GPL-3.0) - [trolo](https://madewithwhat.net/payload/project/trolo/): trolo - an easy to use script for generating Payloads that bypasses antivirus (52 stars, GPL-3.0) - [LogXj](https://madewithwhat.net/payload/project/logxj/): Log4j, POC, POC、、、、Log4j、java、. (51 stars) - [payload-storage-bunny](https://madewithwhat.net/payload/project/payload-storage-bunny/): Payload storage adapter for Bunny.net (50 stars, MIT) - [Pex](https://madewithwhat.net/payload/project/pex/): Python Exploitation is a collection of special tools for providing high quality penetration testing using pure python programming language. (50 stars, MIT) - [payload-plugin-tree-list](https://madewithwhat.net/payload/project/payload-plugin-tree-list/): A plugin for Payload CMS that adds a collapsible Tree list view. (50 stars, MIT) - [vulscanpro](https://madewithwhat.net/payload/project/vulscanpro/): Automatic Web Vulnerability Scanner. (47 stars, GPL-3.0) - [SQL-Injection-Payloads-List](https://madewithwhat.net/payload/project/sql-injection-payloads-list/): SQL Injection Payloads List. (47 stars) - [XSS-Payload](https://madewithwhat.net/payload/project/xss-payload/): 「」XSS Payload List (46 stars, MIT) - [pixqrcodegen](https://madewithwhat.net/payload/project/pixqrcodegen/): Módulo python para gerar payload pix (46 stars, MIT) - [injectra](https://madewithwhat.net/payload/project/injectra/): Injectra injects shellcode payloads into MacOS applications and package installers. (45 stars, MIT) - [payload-sitemap-plugin](https://madewithwhat.net/payload/project/payload-sitemap-plugin/): Sitemap Plugin for PayloadCMS (45 stars, MIT) - [rop-benchmark](https://madewithwhat.net/payload/project/rop-benchmark/): ROP Benchmark is a tool to compare ROP compilers (44 stars) - [bypass-cors](https://madewithwhat.net/payload/project/bypass-cors/): a proxy server to bypass CORS enabled servers (43 stars, MIT) - [mtk-payloads](https://madewithwhat.net/payload/project/mtk-payloads/): Payloads for MediaTek Download Agents (42 stars, AGPL-3.0) - [FlipperZero](https://madewithwhat.net/payload/project/flipperzero/): Various tools for my flipperzero (42 stars, Apache-2.0) - [Rickroll_MODDED_HID](https://madewithwhat.net/payload/project/rickroll-modded-hid/): Awesome modification of the original "Rickroll". Arduino script + Ducky script (41 stars) - [file-upload](https://madewithwhat.net/payload/project/file-upload/): Catalogue de payloads destinés au téléversement de fichiers. Il s'agit d'un ensemble de plusieurs fichiers contenant du code malveillant à utiliser lors des tests d'intrusion, rassemblés en un seul endroit. (41 stars) - [payload-exportcollections-plugin](https://madewithwhat.net/payload/project/payload-exportcollections-plugin/): Provide ability to export collections as CSV or JSON (40 stars, Apache-2.0) - [payload-kanban-board](https://madewithwhat.net/payload/project/payload-kanban-board/): A payload cms plugin for kanban board view (40 stars) - [payload-meilisearch](https://madewithwhat.net/payload/project/payload-meilisearch/): Meilisearch integration plugin for Payload CMS. (39 stars, MIT) - [SQL-XSS](https://madewithwhat.net/payload/project/sql-xss/): A few SQL and XSS attack tools (39 stars) - [Rubber-Ducky-Reverse-Shell](https://madewithwhat.net/payload/project/rubber-ducky-reverse-shell/): Fast & Silent Script For Rubber Ducky To Inject Reverse Shell (37 stars, GPL-3.0) - [WhatsPayloadRCE](https://madewithwhat.net/payload/project/whatspayloadrce/): Whatsapp Automatic Payload Generator [CVE-2019-11932] (35 stars) - [payload-recaptcha-v3](https://madewithwhat.net/payload/project/payload-recaptcha-v3/): This library implements a collection protection in Payload CMS using Google reCAPTCHA v3. (35 stars) - [ps4-ftp](https://madewithwhat.net/payload/project/ps4-ftp/): Improved FTP server payload for PS4 and command line FTP server for Linux. (35 stars) - [winregmitm](https://madewithwhat.net/payload/project/winregmitm/): Perform MiTM attack and remove encryption on Windows Remote Registry Protocol. (35 stars, GPL-2.0) - [nip44](https://madewithwhat.net/payload/project/nip44/): NIP44 encrypted messages for nostr. Spec and implementations (34 stars) - [flow-state](https://madewithwhat.net/payload/project/flow-state/): UI state management with RxJS. (34 stars, MIT) - [AutoIt-PowerShell-Loader](https://madewithwhat.net/payload/project/autoit-powershell-loader/): Download and loader.NET payload (34 stars) - [h-sploit-paylod](https://madewithwhat.net/payload/project/h-sploit-paylod/): H-SPLOIT-PAYLOAD GENERATE METASPLOIT PAYLOAD IN 1 CLICK (33 stars, MIT) - [plugin-password-protection](https://madewithwhat.net/payload/project/plugin-password-protection/): The official password protection plugin for Payload (32 stars) - [CARNOTAURUS](https://madewithwhat.net/payload/project/carnotaurus/): Backdoor for Rubella on Shell's (32 stars, MIT) - [CayenneLPP](https://madewithwhat.net/payload/project/cayennelpp/): Cayenne Low Power Payload (LLP) (32 stars, GPL-3.0) - [HoppEye](https://madewithwhat.net/payload/project/hoppeye/): HoppEye is a simple payload picker for BashBunny based on linking payloads to LED color. (32 stars, MIT) - [rMETAshell](https://madewithwhat.net/payload/project/rmetashell/): rMETAshell takes a shell command and an image, video or text file as input. It then injects the command into the file using metadata comments. After injection, it generates a one-liner execution method for retrieving and executing the injected command from a remote location. (31 stars, AGPL-3.0) - [CVE-2024-37051-EXP](https://madewithwhat.net/payload/project/cve-2024-37051-exp/): CVE-2024-37051 poc and exploit (29 stars) - [plugin-zapier](https://madewithwhat.net/payload/project/plugin-zapier/): The official Zapier plugin for Payload (28 stars, MIT) - [lib2shell](https://madewithwhat.net/payload/project/lib2shell/): Shared library implementations that transform the containing process into a shell when loaded (useful for privilege escalation, argument injection, file overwrites, LD_PRELOAD, etc.). (28 stars, GPL-2.0) - [payload-typesense](https://madewithwhat.net/payload/project/payload-typesense/): A production-ready search plugin that integrates Typesense with Payload CMS, offering fast, typo-tolerant search with real-time synchronization. (28 stars, MIT) - [asv-mavlink](https://madewithwhat.net/payload/project/asv-mavlink/): Mavlink library for.NET (28 stars, MIT) - [atomic-payload](https://madewithwhat.net/payload/project/atomic-payload/): A collection of Payload CMS plugins and tools that can be used to create a website builder in Payload. (28 stars, MIT) - [payload-cmdk](https://madewithwhat.net/payload/project/payload-cmdk/): A powerful command menu plugin for Payload CMS that enhances navigation and accessibility within the admin panel with keyboard shortcuts. (28 stars) - [Code-Cave](https://madewithwhat.net/payload/project/code-cave/): Injects position-dependent code into a code cave in an executable file, and applies relocations. (27 stars) - [payload-google-map-autocomplete-places](https://madewithwhat.net/payload/project/payload-google-map-autocomplete-places/): A plugin for payload cms for google maps auto complete (27 stars, MIT) - [CVE-2022-21907](https://madewithwhat.net/payload/project/cve-2022-21907/): CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube. (26 stars, GPL-3.0) - [certexfil](https://madewithwhat.net/payload/project/certexfil/): Exfiltration based on custom X509 certificates (26 stars, MIT) - [penetration-testing](https://madewithwhat.net/payload/project/penetration-testing/): Offensive penetration testing. Perform multiple attack types against web applications, vulnerable programs and OSes in predefined and safe test environment (26 stars) - [payload-imagekit](https://madewithwhat.net/payload/project/payload-imagekit/): Send Payload CMS uploads and deletes to ImageKit (25 stars) - [payload-iframe-tabs-plugin](https://madewithwhat.net/payload/project/payload-iframe-tabs-plugin/): Payload plugin that lets you add custom tabs for iframes, useful for things like Figma and other embeds (25 stars, MIT) - [sts](https://madewithwhat.net/payload/project/sts/): A fully open-source status page with Gatus backend and Payload CMS (25 stars, Apache-2.0) - [Python-Obfuscation-Framework](https://madewithwhat.net/payload/project/python-obfuscation-framework/): Obfuscate Python code, stage payloads, and evade defenses (25 stars, GPL-3.0) - [yet-another-status-page](https://madewithwhat.net/payload/project/yet-another-status-page/): A modern, open-source status page built with Next.js and PayloadCMS, designed for flexible and reliable infrastructure monitoring. (25 stars, MIT) - [payloadcms-plugin-image-optimizer](https://madewithwhat.net/payload/project/payloadcms-plugin-image-optimizer/): Automatic image optimization plugin for PayloadCMS 3.x — compress & convert uploads to modern formats (WebP, AVIF) on the fly, including all size variants. Works with cloud storage. (24 stars, MIT) - [simple-payload-generator](https://madewithwhat.net/payload/project/simple-payload-generator/): SPG: Simple MSFVenom Payload Generator (24 stars, BSD-3-Clause) - [payload-hash-upload](https://madewithwhat.net/payload/project/payload-hash-upload/): Append a hash to upload filenames in Payload CMS, and optimize your CDN caching strategy (23 stars, MIT) - [HookInterceptor](https://madewithwhat.net/payload/project/hookinterceptor/): Unity + StreamDeck – Call the Unity Editor using deep links with custom payloads (23 stars, MIT) - [escort](https://madewithwhat.net/payload/project/escort/): ssshh its a secret;) (22 stars, MIT) - [VisualPayload](https://madewithwhat.net/payload/project/visualpayload/): A joke program that blasts the screen with visual junk. Computer stroke simulator. (22 stars) - [kusanagi](https://madewithwhat.net/payload/project/kusanagi/): Kusanagi is a bind and reverse shell payload generator with obfuscation and badchar support. (22 stars, MIT) - [blitzkloud](https://madewithwhat.net/payload/project/blitzkloud/): Cloudflare compatible Reverse HTTP Shell w/ AES & Domain Fronting (via SNI) Support (22 stars) - [DarkCrypter](https://madewithwhat.net/payload/project/darkcrypter/): DarkCrypter encrypts your files and generates undetectable payloads to evade all anti-virus vendors. (21 stars, GPL-3.0) - [wormnest](https://madewithwhat.net/payload/project/wormnest/): A Web Server to hide stuff (21 stars, MIT) - [BadUSB-Payload-Encoder](https://madewithwhat.net/payload/project/badusb-payload-encoder/): Malwarekid python BadUSB payload encoder for generating powershell script in bas64 (21 stars, MIT) - [TTNetworkManager](https://madewithwhat.net/payload/project/ttnetworkmanager/): SSL pinning that TikTok/ (21 stars) - [BatSploit](https://madewithwhat.net/payload/project/batsploit/): Exploitation Tool For Windows Using Batch and Powershell (21 stars) - [Digispark-Meterpreter-Framework](https://madewithwhat.net/payload/project/digispark-meterpreter-framework/): A framework which writes your Digispark arduino code for a specific metasploit payload. (21 stars, MIT) - [BadUSB_Downloader](https://madewithwhat.net/payload/project/badusb-downloader/): Download & Execute file using DigiSpark ATtiny85, RubberDucky, Arduino Pro Micro (20 stars) - [dransomware](https://madewithwhat.net/payload/project/dransomware/): USB Rubber Ducky Script, Dransomware is ransomware which will encrypt data without root privileges. (20 stars) - [bin2js](https://madewithwhat.net/payload/project/bin2js/): Fast.bin to.js converter for use with sleirsgoevy's PS4 jailbreaks. (20 stars) - [payload-injector-generator](https://madewithwhat.net/payload/project/payload-injector-generator/): Auto Create Payload HTTP Injectior With Input Bug (20 stars) - [clickfix-builder](https://madewithwhat.net/payload/project/clickfix-builder/): ClickFix / Fake Captcha Builder (GUI) with powershell payload - Dual Mode Social Engineering Toolkit (20 stars, Apache-2.0) - [payloadkit](https://madewithwhat.net/payload/project/payloadkit/): An offensive security framework for writing payloads (20 stars, BSD-3-Clause) - [ShellCrypt](https://madewithwhat.net/payload/project/shellcrypt/): AES-256-CBC shellcode encryption tool. (20 stars, MIT) - [Tool-Avenge](https://madewithwhat.net/payload/project/tool-avenge/): A project worth exploring. (20 stars) - [plugin-adaptive-bitrate-videos](https://madewithwhat.net/payload/project/plugin-adaptive-bitrate-videos/): Payload CMS plugin enabling adaptive bitrate videos across collections. Automatically segments uploads, creates multiple resolutions, and generates HLS manifests. Customizable settings for each collection. (20 stars, MIT) - [CVE-2021-41773_CVE-2021-42013](https://madewithwhat.net/payload/project/cve-2021-41773-cve-2021-42013/): Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE (20 stars) - [Reverse_Shell_Generator](https://madewithwhat.net/payload/project/reverse-shell-generator/): Bash script to generate reverse shell payloads (19 stars) - [vulcan](https://madewithwhat.net/payload/project/vulcan/): A PowerShell script that simplifies life and therefore... phishing. (19 stars, BSD-3-Clause) - [MG](https://madewithwhat.net/payload/project/mg/): MG community edition is an open source pentesting tool to generate payloads for HID attacks. (19 stars, Apache-2.0) - [venom](https://madewithwhat.net/payload/project/venom/): the venom framework is a framework made in ruby filled with tools for wireless hacking, normal terminal commands, metasploit payloads and more i do plan on adding more things to it in the future if you would like to see updates on this and other tools i make follow me on instagram: @tuf_unkn0wn (19 stars, Apache-2.0) - [PayloadsOfAllTheThings](https://madewithwhat.net/payload/project/payloadsofallthethings/): A collection of payloads for different vulnerabilities, best payload lists in one repository (18 stars, MIT) - [payload-label-popover](https://madewithwhat.net/payload/project/payload-label-popover/): A plugin to add descriptive popovers to field labels in Payload. (18 stars, MIT) - [WiFi-Remote-Display-ADV](https://madewithwhat.net/payload/project/wifi-remote-display-adv/): Ultra-low latency screen mirroring payload tool for M5Stack Cardputer ADV (18 stars) - [Delivery-Drone-Control](https://madewithwhat.net/payload/project/delivery-drone-control/): MATLAB and Simulink code for controlling delivery drone (18 stars, MIT) - [HatAsm](https://madewithwhat.net/payload/project/hatasm/): HatAsm is a powerful assembler and disassembler that provides support for all common architectures. (18 stars, MIT) - [waf_repeater](https://madewithwhat.net/payload/project/waf-repeater/): WAF (Web Application Firewall) payload (17 stars) - [Attiny85_payloads](https://madewithwhat.net/payload/project/attiny85-payloads/): digispark Attiny 85 payloads and scripts (17 stars, MIT) - [CorporalKraken](https://madewithwhat.net/payload/project/corporalkraken/): Docker Payloads (Bypass) Data at the endpoint when running NestJS APK. (17 stars, MIT) - [payload-warding](https://madewithwhat.net/payload/project/payload-warding/): A Collections / Globals Backed RBAC Plugin for Payload the Headless CMS (17 stars, MIT) - [go-implant](https://madewithwhat.net/payload/project/go-implant/): A flexible cross-platform post-exploitation agent written in Go with basic functionalities (17 stars) - [ExceptionHandlerPayload](https://madewithwhat.net/payload/project/exceptionhandlerpayload/): Kernel payload to automatically quit to XMB if a Playstation 3 user-land thread crashed CEX/DEX/HEN (17 stars, MIT) - [typesense-search](https://madewithwhat.net/payload/project/typesense-search/): A powerful, production-ready search plugin that integrates Typesense with Payload CMS, providing lightning-fast, typo-tolerant search capabilities with real-time synchronization. (17 stars, MIT) - [plumber](https://madewithwhat.net/payload/project/plumber/): Windows payload written in C++, gives total control to the infected machine via reverse-TCP sockets from a web application (17 stars) - [Blueprint](https://madewithwhat.net/payload/project/blueprint/): Templating with sinister modules (16 stars, GPL-3.0) - [Digispark-scripts](https://madewithwhat.net/payload/project/digispark-scripts/): Digispark scripts (16 stars) - [Reverse-Shell-From-Word-Document](https://madewithwhat.net/payload/project/reverse-shell-from-word-document/): This is a repository containing code to generate a PowerShell payload to access PCs remotely. For more information check this out (16 stars) - [Payloads_Tool_box](https://madewithwhat.net/payload/project/payloads-tool-box/): At this repo you can find any tools, tricks or templates for general penetration testing assesment (16 stars) - [PayloadSiteForPenTesters](https://madewithwhat.net/payload/project/payloadsiteforpentesters/): This is a site I made for easily hosting tools and payload over apache2 on Kali Linux so they are always ready to go. These are a collection of tools that can be downloaded with a site that is browsable for GUI situations. (16 stars, MIT) - [Payload-PC104](https://madewithwhat.net/payload/project/payload-pc104/): Payload board schematic and footprint for the SUCHAI 2 and 3. (16 stars, GPL-3.0) - [Quack](https://madewithwhat.net/payload/project/quack/): Automatic Ducky Payload Generator (16 stars) - [payload-media-gallery](https://madewithwhat.net/payload/project/payload-media-gallery/): Additional layout views for media collection with lightbox gallery, quick edit, multi-select and more. (16 stars) - [pinkcord](https://madewithwhat.net/payload/project/pinkcord/): a virus project that uses discord as a reverse shell, has a lot of functions and is easy to use (16 stars, Apache-2.0) - [nem-apps-lib](https://madewithwhat.net/payload/project/nem-apps-lib/): Semantic Java API Library for NEM Platform (16 stars, MIT) - [bufflow](https://madewithwhat.net/payload/project/bufflow/): A collection of code examples e.g. a buffer overflow + exploit, crypter, shellcodes and more. (16 stars) - [UM-NIDS-Tool](https://madewithwhat.net/payload/project/um-nids-tool/): The Unified Multimodal NIDS Dataset Tool performs the standardization of network intrusion detection datasets by extracting comprehensive flow, payload, and contextual features from raw PCAP files, ensuring consistency across datasets and enhancing machine learning-driven threat detection and analysis. (16 stars) - [payload-plugin-ai-chat](https://madewithwhat.net/payload/project/payload-plugin-ai-chat/): ChatGPT-like Plugin for Payload (16 stars, MIT) - [mine4me](https://madewithwhat.net/payload/project/mine4me/): mine4me is BashBunny payload makes your target system mine Monero for you. Spread payload in multiple systems to acquire more Monero. (15 stars) - [cordetfw](https://madewithwhat.net/payload/project/cordetfw/): C Implementation of a Software Framework for Service-Oriented Applications with PUS Support (15 stars, MPL-2.0) - [DEDSEC_CLICKFIX](https://madewithwhat.net/payload/project/dedsec-clickfix/): CLICKFIX is a Linux-based social engineering tool that delivers payloads using a ClickFix (15 stars) - [payload-doctor](https://madewithwhat.net/payload/project/payload-doctor/): Static security & correctness linter for Payload CMS. Zero-config, deterministic, ts-morph-based. Catches access-control gaps, unsafe Local API usage & richtext render risks. npx-runnable. (15 stars, MIT) - [payload_estimation](https://madewithwhat.net/payload/project/payload-estimation/): Robot payload estimation, based on: C. G. Atkeson, C. H. An, and J. M. Hollerbach, “Estimation of Inertial Parameters of Manipulator Loads and Links,” Int. J. Rob. Res., vol. 5, no. 3, pp. 101–119, Sep. 1986 (14 stars) - [CTFs](https://madewithwhat.net/payload/project/ctfs/): Writeups & Walkthroughs of various CTF challenges and boxes (14 stars) - [DivinityProtector](https://madewithwhat.net/payload/project/divinityprotector/): .NET & Native crypter with modern GUI (14 stars) - [Mr.Link](https://madewithwhat.net/payload/project/mr-link/): Silent Screenshot Capture | Post Exploitation Payload | VB.NET (13 stars, GPL-3.0) - [N3h4V1ru5](https://madewithwhat.net/payload/project/n3h4v1ru5/): Just a Rick Roll with a left over poisoned love letter. (13 stars) - [wifiduck](https://madewithwhat.net/payload/project/wifiduck/): Wireless keystroke injection attack platform # WifiDuck (12 stars, GPL-3.0) - [payload-zitadel-plugin](https://madewithwhat.net/payload/project/payload-zitadel-plugin/): Extends `payloadcms` with the ability to login through Zitadel (12 stars, Apache-2.0) - [InvisMalware](https://madewithwhat.net/payload/project/invismalware/): A Malware Evasion Technique, shellcode generation, syntax modification, anti-dynamic analysis & PE header modification. (12 stars, MIT) - [Advanced-Payload-Concealment-and-Security-Analysis](https://madewithwhat.net/payload/project/advanced-payload-concealment-and-security-analysis/): Demonstrate and showcasing how you can hide payload or secret message inside an image, audio, and PDF file and how an unethical person might use the advantage of sending a malicious image, audio, or PDF file to a victim to gain control or to do other malicious activities. (12 stars) - [glua_vtf_backdooring](https://madewithwhat.net/payload/project/glua-vtf-backdooring/): Injecting lua code in working VTF files and then running it (12 stars) - [band-4-window-creation](https://madewithwhat.net/payload/project/band-4-window-creation/): injects a payload into explorer.exe, which creates a window in band 4 (ZBID_IMMERSIVE_NOTIFICATION) (12 stars, MIT) - [Open_Redirect_Payload_List](https://madewithwhat.net/payload/project/open-redirect-payload-list/): Open Redirect Vulnerability Payload List (12 stars, MIT) - [payload-better-preview](https://madewithwhat.net/payload/project/payload-better-preview/): Better live preview for Payload CMS — hover highlighting with block identification, bi-directional admin/preview sync, and smooth transitions. (12 stars, MIT) - [DEDSEC_M2PDF](https://madewithwhat.net/payload/project/dedsec-m2pdf/): embed binary or ELF malware into PDF files without corrupting the original document. (12 stars, MIT) - [prober](https://madewithwhat.net/payload/project/prober/): Pentester's toolbox (12 stars) - [TokenFucker](https://madewithwhat.net/payload/project/tokenfucker/): Token Stealing Tool for Windows and Linux (12 stars, Apache-2.0) - [android-java-payload](https://madewithwhat.net/payload/project/android-java-payload/): Simple, reliable, persistent, undetectable Android reverse shell payload, compatible with Android 8, 9, 10, 11, 12 and 13 (12 stars) - [pwnKit](https://madewithwhat.net/payload/project/pwnkit/): pwnKit: Privilege Escalation USB-Rubber-Ducky payload, which exploits CVE-2021-4034 in less than 10sec's and spawns root shell for you. (11 stars) - [Safe-rooting-the-Nothing-Phone-_1_](https://madewithwhat.net/payload/project/safe-rooting-the-nothing-phone-1/): How to safe rooting the Nothing Phone (1) (11 stars) - [payload-code-block-feature](https://madewithwhat.net/payload/project/payload-code-block-feature/): A workaround for using @lexical/code with PayloadCMS until the core team integrates into the official package. (11 stars, MIT) - [Shrek](https://madewithwhat.net/payload/project/shrek/): Bash Script to automate Metasploit, Payload & Reverse Shell Generation. (11 stars) - [rcekit](https://madewithwhat.net/payload/project/rcekit/): RCEKit — an RCE testing toolkit for authorized security testing. Generate context- and sink-aware payloads across 14 environments, deliver them (Burp/Nuclei export or the built-in --verify harness), and auto-confirm execution — including blind/out-of-band callbacks via the built-in listener. (11 stars, MIT) - [black_veil](https://madewithwhat.net/payload/project/black-veil/): A simple pseudo-crypter for python code. (10 stars) - [payloadcms-website-template](https://madewithwhat.net/payload/project/payloadcms-website-template/): A multi-page website template with PayloadCMS 3.0 and layout builder (10 stars, MIT) - [SCCT-Trainer](https://madewithwhat.net/payload/project/scct-trainer/): A Splinter Cell Chaos Theory Multi-Hack built with x86 Assembly. (10 stars, MIT) - [persistentReverseDucky](https://madewithwhat.net/payload/project/persistentreverseducky/): persistentReverseDucky: provides you persistent reverse shell remotely/locally by creating non-root systemd service within 10 secs. (10 stars) - [sia-payload](https://madewithwhat.net/payload/project/sia-payload/): MultiPlatform (mac,linux,windows) Payload For Hack System! (10 stars, GPL-3.0) - [DuckyLogger](https://madewithwhat.net/payload/project/duckylogger/): DuckyLogger: DuckyLogger is a Key Logger which captures every key stroke of traget and send them to attacker. (10 stars) - [payload-training-app](https://madewithwhat.net/payload/project/payload-training-app/): Open-source coaching app built with Payload CMS and Next.js. Coaches manage training plans in the admin; clients log workouts on mobile. (10 stars, MIT) - [obscure-usb](https://madewithwhat.net/payload/project/obscure-usb/): Obscure-USB is a program that generates BadUSB payloads, establishing a reverse shell between a Linux machine and a Windows target. (10 stars, GPL-3.0) - [payload-dll-injector](https://madewithwhat.net/payload/project/payload-dll-injector/): A stealthy Payload (and/or DLL) injector for Windows 10/11, capable of injecting a msfvenom payload (or specified DLL) into a suspended process and evade detection (10 stars, GPL-3.0) ## Testing (15) - [AllAboutBugBounty](https://madewithwhat.net/payload/project/allaboutbugbounty/): All about bug bounty (bypasses, payloads, and etc) (6,804 stars) - [pentest-guide](https://madewithwhat.net/payload/project/pentest-guide/): Penetration tests guide based on OWASP including test cases, resources and examples. (2,815 stars, GPL-3.0) - [ezXSS](https://madewithwhat.net/payload/project/ezxss/): ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. (2,322 stars, MIT) - [link](https://madewithwhat.net/payload/project/link/): link is a command and control framework written in rust (579 stars, AGPL-3.0) - [LNKUp](https://madewithwhat.net/payload/project/lnkup/): Generates malicious LNK file payloads for data exfiltration (457 stars) - [Arcane](https://madewithwhat.net/payload/project/arcane/): Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories. (155 stars) - [Writeups](https://madewithwhat.net/payload/project/writeups/): This repository contains writeups for various CTFs I've participated in (Including Hack The Box). (155 stars) - [xss-payload-list](https://madewithwhat.net/payload/project/xss-payload-list/): This project aims to provide a comprehensive resource for understanding and testing Cross-Site Scripting (XSS) vulnerabilities, one of the OWASP Top 10 security risks. It is designed to be a useful resource for security researchers, penetration testers, and developers. (130 stars) - [advtools](https://madewithwhat.net/payload/project/advtools/): Automated PowerHacker Suite: Your all-in-one solution for ethical hacking. Conduct comprehensive network mapping, vulnerability assessments, password cracking, wireless network analysis, social engineering simulations, and more. Generate real-time reports with actionable insights to identify vulnerabilities and recommend countermeasures. (86 stars, MIT) - [sql-injection-payload-list](https://madewithwhat.net/payload/project/sql-injection-payload-list/): The primary goal of this project is to explain SQL Injection (one of the OWASP Top 10 vulnerabilities) and to provide a beneficial resource for the security community. (76 stars, MIT) - [road-to-hacking](https://madewithwhat.net/payload/project/road-to-hacking/): ¿Quieres empezar en el mundo hacking? En esta revista te enseño a instalar Kali Linux desde cero y a manipular herramientas esenciales en el Hacking Ético. (74 stars) - [jarbou3](https://madewithwhat.net/payload/project/jarbou3/): Jarbou3 is rat tool coded in python with C&C which can accept multiple connections from clients (29 stars, MIT) - [Shells](https://madewithwhat.net/payload/project/shells/): List of payloads: reverse shell, bind shell, webshell. (16 stars) - [EchoFi_USB_rubber_ducky](https://madewithwhat.net/payload/project/echofi-usb-rubber-ducky/): A RED TEAM' rubber ducky USB. By this USB u can inject malicious script or install malware in any pc or laptop (12 stars) - [icmp-bindshell](https://madewithwhat.net/payload/project/icmp-bindshell/): Experimental python3.x based ICMP bind shell listener using scapy and windows 'compatible' (10 stars, GPL-2.0) ## AI & ML (10) - [payload-wizard](https://madewithwhat.net/payload/project/payload-wizard/): AI assistant that utilizes GPT language models to interpret and generate cybersecurity payloads (285 stars, MIT) - [skills](https://madewithwhat.net/payload/project/skills/): Payload Skills to assist AI agents (135 stars) - [Loki.Rat](https://madewithwhat.net/payload/project/loki-rat/): Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording, lockscreen, and locate options. Loki.Rat is a Python Remote Access Tool. (76 stars) - [Crawllama](https://madewithwhat.net/payload/project/crawllama/): CrawlLama is an local AI agent that answers questions via Ollama and integrates web- and RAG-based research. (71 stars) - [ai](https://madewithwhat.net/payload/project/ai/): Agentic Workflow Platform (38 stars, MIT) - [deeplearning-network-traffic](https://madewithwhat.net/payload/project/deeplearning-network-traffic/): Network Traffic Identification with Convolutional Neural Networks (27 stars, MIT) - [analystOS](https://madewithwhat.net/payload/project/analystos/): analystOS - AI research platform for stocks and crypto with Web UI + Notion automation. Upload docs, scrape URLs, chat with research via RAG. Powered by OpenRouter (50+ models). (21 stars) - [A-Deep-Learning-Approach-to-Web-Application-Firewall](https://madewithwhat.net/payload/project/a-deep-learning-approach-to-web-application-firewall/): Avoid malicious payloads in your webapp with machine learning! (21 stars) - [payload-plugin-ai](https://madewithwhat.net/payload/project/payload-plugin-ai/): Currently just does embeddings! (15 stars, MIT) - [mangyaWAF](https://madewithwhat.net/payload/project/mangyawaf/): A Machine Learning Based Web Application firewall (10 stars) ## E-commerce (10) - [payload-ecommerce-template](https://madewithwhat.net/payload/project/payload-ecommerce-template/): E-commerce platform template using PayloadCMS, Next.js, TypeScript and TailwindCSS for modern online stores. Includes payment and delivery integrations (168 stars, MIT) - [next-digital-marketplace](https://madewithwhat.net/payload/project/next-digital-marketplace/): Digital marketplace it's a next.js full stack application (e-commerce platform). Digital Marketplace is a sophisticated full-stack e-commerce platform designed to deliver a seamless shopping experience for users. It incorporates cutting-edge technologies and frameworks to ensure robustness, efficiency, and scalability. (92 stars, MIT) - [pix-dynamic-payload-generator.net](https://madewithwhat.net/payload/project/pix-dynamic-payload-generator-net/): Implementação em.net para auxiliar na geração de payloads e QRCodes para pagamento PIX, o sistema de pagamento instantâneo do Brasil. (67 stars, MIT) - [pix-payload-generator.net](https://madewithwhat.net/payload/project/pix-payload-generator-net/): Gerar payload para qrcode estático PIX. (Sistema de pagamento instantâneo do Brasil) Sem a necessidade de conexão com um PSP. (61 stars, MIT) - [e-commerce](https://madewithwhat.net/payload/project/e-commerce/): An Open-source E Commerce Store built with Payload and Next.js (54 stars, MIT) - [digibee-marketplace](https://madewithwhat.net/payload/project/digibee-marketplace/): DigiBee is a Full-Stack built with Next.js for frontend and Payload as backend. It is a modern digital product marketplace where you can sell your digital products like e-books, courses, templates, etc. It is a fully functional marketplace with a lot of features. (49 stars, MIT) - [rdx](https://madewithwhat.net/payload/project/rdx/): Like Redux, but smaller (34 stars) - [payload-cms-ecommerce](https://madewithwhat.net/payload/project/payload-cms-ecommerce/): The official Payload E-Commerce Template (33 stars) - [amerta](https://madewithwhat.net/payload/project/amerta/): Amerta is a modern, developer-first e-commerce framework built on top of Payload CMS and Next.js. It is designed to replace legacy platforms with a fully typed, scalable architecture that provides absolute control over the storefront and admin experience. (32 stars, MIT) - [payload-qrcode-pix](https://madewithwhat.net/payload/project/payload-qrcode-pix/): Pix payload generator and QR Code with PHP (11 stars) ## Docs (9) - [RedTeam-Tools](https://madewithwhat.net/payload/project/redteam-tools/): Tools and Techniques for Red Team / Penetration Testing (9,441 stars) - [AwesomeXSS](https://madewithwhat.net/payload/project/awesomexss/): Awesome XSS stuff (5,131 stars, MIT) - [rudyjs](https://madewithwhat.net/payload/project/rudyjs/): PenTest Education: R-U-DEAD-YET? DOS Attack Implementation in Node.JS (151 stars, Apache-2.0) - [digiQuack](https://madewithwhat.net/payload/project/digiquack/): DuckyScript language to DigiSpark payload converter (Online / C++) (145 stars, MIT) - [SecNN-Wiki](https://madewithwhat.net/payload/project/secnn-wiki/): Wiki&--Web、、、(Android)、、RCE、IOT。 (84 stars) - [SimpleCrypter](https://madewithwhat.net/payload/project/simplecrypter/): A simple cryptor for.NET/Native files with Injection and obfuscation (55 stars, GPL-3.0) - [SecRep](https://madewithwhat.net/payload/project/secrep/): SecRep Is a Repository That Contain Useful Intrusion, Penetration and Hacking Archive Including Tools List, Cheetsheet and Payloads (19 stars, GPL-3.0) - [PS4Offsets-With-Payloads](https://madewithwhat.net/payload/project/ps4offsets-with-payloads/): PS4 Offsets Documentation (15 stars, GPL-3.0) - [AymanSecNotes](https://madewithwhat.net/payload/project/aymansecnotes/): This repository contains all my notes. Feel free to use them, share them or modify them. (10 stars) ## APIs (9) - [datamodel-code-generator](https://madewithwhat.net/payload/project/datamodel-code-generator/): Generate Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON/YAML/CSV. (3,965 stars, MIT) - [website](https://madewithwhat.net/payload/project/website/): The official Next.js website for payloadcms.com (623 stars, MIT) - [openapi-sampler](https://madewithwhat.net/payload/project/openapi-sampler/): Tool for generation samples based on OpenAPI(fka Swagger) payload/response schema (228 stars, MIT) - [ADR](https://madewithwhat.net/payload/project/adr/): ADR is a trojan that retrieves all information on the computer and all data stored in applications using chormuim. It recovers cookies, tokens, passwords and saved bank cards. This malware is undetectable by Windows Defender, Chrome, Virustotal (4/71). (25 stars) - [spotexfil](https://madewithwhat.net/payload/project/spotexfil/): A simple way to exfiltrate data using spotify API (19 stars) - [dalal](https://madewithwhat.net/payload/project/dalal/): BYOL* Payload Transformation Service (13 stars, MIT) - [PS4API_5.0x_Server](https://madewithwhat.net/payload/project/ps4api-5-0x-server/): PS4 API for 5.0x Firmware. Originally Developed By Bisoon for 4.55 (11 stars, GPL-3.0) - [CVE-2023-34362](https://madewithwhat.net/payload/project/cve-2023-34362/): POC for CVE-2023-34362 affecting MOVEit Transfer (10 stars, MIT) - [payload-plugin-openapi](https://madewithwhat.net/payload/project/payload-plugin-openapi/): OpenAPI 3.0/3.1/3.2 spec generator for Payload CMS, with Scalar/Swagger UI. (10 stars, MIT) ## Templates (9) - [remix-server](https://madewithwhat.net/payload/project/remix-server/): Monorepo template with Remix and Payload (133 stars, MIT) - [payload-better-auth-starter](https://madewithwhat.net/payload/project/payload-better-auth-starter/): A production-ready PayloadCMS starter with Better Auth, modern UI components, and full-stack development tools. (114 stars) - [payload-starter](https://madewithwhat.net/payload/project/payload-starter/): Open Source SaaS starter for creating applications with Next.js and Payload (95 stars) - [binarystarter-angular](https://madewithwhat.net/payload/project/binarystarter-angular/): Angular Full Stack Boilerplate Starter with PayloadCMS, Nx and Express. Free Open-Source Web App Boilerplate. (92 stars, MIT) - [payload-3-boilerplate](https://madewithwhat.net/payload/project/payload-3-boilerplate/): Payload CMS V3 Boilerplate for Railway, by FUNKYTON (32 stars) - [dd-starter](https://madewithwhat.net/payload/project/dd-starter/): Payload CMS starter template with Puck visual page editing, page-tree, and Better Auth (30 stars) - [pay](https://madewithwhat.net/payload/project/pay/): Payload starter by 9d8 (25 stars, MIT) - [payload-clerk-example](https://madewithwhat.net/payload/project/payload-clerk-example/): Payload CMS and Clerk example (19 stars) - [payload-cms-boilerplate](https://madewithwhat.net/payload/project/payload-cms-boilerplate/): Hello world! This is a super powerful boilerplate built with Payload CMS 3.64.0 and Next.js 16! Everything is ready to get started right away! (19 stars) ## Mobile (8) - [android-ota-payload-extractor](https://madewithwhat.net/payload/project/android-ota-payload-extractor/): A fast & natively cross-platform Android OTA payload extractor written in Go (437 stars, MIT) - [flipperzero-badUSB](https://madewithwhat.net/payload/project/flipperzero-badusb/): A collection of selected badUSB script for Flipper Zero, written by me. This repo is always Work In Progress. (374 stars, MIT) - [violet_Box](https://madewithwhat.net/payload/project/violet-box/): Android (254 stars, GPL-3.0) - [-System-Android-RAT-Trojan](https://madewithwhat.net/payload/project/system-android-rat-trojan/): A project worth exploring. (29 stars) - [Deadfi_deauther-](https://madewithwhat.net/payload/project/deadfi-deauther/): This tool will allows u to deauth or kick off an specific device from an given AP (24 stars) - [Chimera](https://madewithwhat.net/payload/project/chimera/): Payload injector and HID emulator for Android like Hak5 and rubber ducky (22 stars, MIT) - [tfp0](https://madewithwhat.net/payload/project/tfp0/): tfp0 (task for pid 0) is a kernel task port that grants full control over the iOS device's kernel. Access to this port is necessary for developing many types of exploits, including jailbreaks. (14 stars) - [Persistent-Exploit](https://madewithwhat.net/payload/project/persistent-exploit/): Guide to follow the steps to run an exploit of Metasploit and upload a persistent reverse-shell file (12 stars, CC-BY-SA-4.0) ## Dashboards (7) - [CHAOS](https://madewithwhat.net/payload/project/chaos/): CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems. (2,815 stars, MIT) - [RomBuster](https://madewithwhat.net/payload/project/rombuster/): RomBuster is a router exploitation tool that allows to disclosure network router admin password. (556 stars, MIT) - [payload-dashboard-analytics](https://madewithwhat.net/payload/project/payload-dashboard-analytics/): Add analytics charts and information directly in your Payload admin. (178 stars, MIT) - [ForceAdmin](https://madewithwhat.net/payload/project/forceadmin/): Collection of script templates to create infinite UAC prompts forcing a user to run as admin (119 stars, GPL-3.0) - [BadUSB_adminAccountCreator](https://madewithwhat.net/payload/project/badusb-adminaccountcreator/): This script allows you to create a hidden admin account on your victim's PC. (44 stars, MIT) - [SysX](https://madewithwhat.net/payload/project/sysx/): SysX (RAT or RMM) is for educational or internal demo use only. Do not upload this binary to VirusTotal or other public sandboxes. (18 stars, MIT) - [payload-nav-studio](https://madewithwhat.net/payload/project/payload-nav-studio/): Payload CMS plugin — customizable admin sidebar navigation with drag & drop, per-user preferences, 70+ icons, i18n ready (10 stars, MIT) ## Authentication (7) - [payload-auth-plugin](https://madewithwhat.net/payload/project/payload-auth-plugin/): Authentication plugin for Payload CMS (303 stars, MIT) - [payload-oauth2](https://madewithwhat.net/payload/project/payload-oauth2/): Plugin for PayloadCMS to integrate OAuth2 (197 stars, MIT) - [python-remote-session-lab-poc](https://madewithwhat.net/payload/project/python-remote-session-lab-poc/): Educational lab project exploring secure remote session design, authentication flows, logging, and detection considerations. Built for defensive research and blue-team understanding. (175 stars, MIT) - [payload-better-auth](https://madewithwhat.net/payload/project/payload-better-auth/): Better Auth, one plugin away from PayloadCMS. (74 stars, AGPL-3.0) - [payload-better-auth](https://madewithwhat.net/payload/project/payload-better-auth/): Better Auth adapter and plugins for Payload CMS (61 stars, MIT) - [payload-simple-rbac](https://madewithwhat.net/payload/project/payload-simple-rbac/): A simple plugin to help you manage permissions in Payload with user roles. (41 stars, MIT) - [payload-gatekeeper](https://madewithwhat.net/payload/project/payload-gatekeeper/): The ultimate access control gatekeeper for Payload CMS v3 - Advanced RBAC with wildcard support, auto role assignment, and flexible configuration (23 stars, MIT) ## Blogs (7) - [PyHmmm](https://madewithwhat.net/payload/project/pyhmmm/): Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a tutorial sample (86 stars) - [turbopress](https://madewithwhat.net/payload/project/turbopress/): Astro + Payload CMS Turborepo (79 stars, MPL-2.0) - [payload-astro-website-template](https://madewithwhat.net/payload/project/payload-astro-website-template/): A fully featured template for building performant and scalable content-driven websites with Payload CMS and Astro. (36 stars) - [payload-instagram-plugin](https://madewithwhat.net/payload/project/payload-instagram-plugin/): This plugin allows you to use an instagram connected feed as content to be shown inside payload blog. (23 stars, MIT) - [go-payloadcms](https://madewithwhat.net/payload/project/go-payloadcms/): GoLang client library & SDK for Payload CMS (18 stars, MIT) - [nostarch-evasion-engineering](https://madewithwhat.net/payload/project/nostarch-evasion-engineering/): This is the companion repo for a copy of all code, references, and extras noted by the Evasion Engineering book from NoStarch Publishing by Dennis Chow and Michael LaSalvia (16 stars, MIT) - [payload-alternative-lexical-editor](https://madewithwhat.net/payload/project/payload-alternative-lexical-editor/): An alternative Lexical rich text editor for Payload CMS. Meta's Lexical rich text editor. (12 stars, MIT) ## UI Kits (6) - [payload-theme-quantum-leap](https://madewithwhat.net/payload/project/payload-theme-quantum-leap/): A demo theme for Payload CMS (74 stars) - [Aura.Payload](https://madewithwhat.net/payload/project/aura-payload/): A Domain Payload implementation. (55 stars, MIT) - [BFpilot](https://madewithwhat.net/payload/project/bfpilot/): Lightweight PS5 file manager that is browser based (27 stars) - [payload-components](https://madewithwhat.net/payload/project/payload-components/): Payload Components: registry-backed Payload CMS blocks installed wired, not pasted. (17 stars, MIT) - [payload-cms-custom-related-select-example](https://madewithwhat.net/payload/project/payload-cms-custom-related-select-example/): example of dynamic select component pairs in payload 3 cms (13 stars) - [payload-extra-fields](https://madewithwhat.net/payload/project/payload-extra-fields/): A collection of customizable, accessible custom fields built specifically for PayloadCMS. Each field includes both the UI component and utility function to easily integrate into your schemas. (12 stars, MIT) ## Real-time (1) - [payload-chat](https://madewithwhat.net/payload/project/payload-chat/): Payload on the backend with a custom endpoint using (Server-Sent Events) SSE to send updates to the client, The client listens for updates using the EventSource API. (27 stars)