
weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

XSS payloads designed to turn alert(1) into P1

Remote operations commands implemented using Beacon Object Files

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Research code & papers from members of vx-underground.

Explanation and full RCE PoC for CVE-2025-55182

Shellcode Compiler

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

This repo covers some code execution and AV Evasion methods for Macros in Office documents

Use a Fake image.jpg to exploit targets (hide known file extensions)

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Fast C++ ROP gadget finder for PE/ELF/Mach-O binaries across x86/x64/ARM/ARM64 architectures, enabling efficient return-oriented programming chain…

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

SharpSploit is a .NET post-exploitation library written in C#

Hide your Powershell script in plain sight. Bypass all Powershell security features