Pentest Payload
Generator

Generate weaponized files for authorized security testing. XXE injections, image metadata payloads, polyglot files, and archive attacks.

4 categories 14 generators 16 files generated

Archive Attacks

Generate malicious archives with path traversal, symlinks, and decompression bombs.

Document Injection

Inject XXE, JavaScript, and other payloads into document formats like XLSX, DOCX, and PDF.

Image Metadata

Embed payloads in image metadata — PNG comments, JPEG EXIF, SVG scripts, and GIF comment blocks.

Polyglot Files

Create files that are valid in multiple formats simultaneously, bypassing content-type validation.