
endgame
ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations
Tools for creating and customizing malicious code or instructions to execute after exploitation.

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations


Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.

POC for CVE-2026-23744 for a python revshell

PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

CVE-2026-50522 PoC

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

Connect Cursor, Copilot & Claude AI directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using…

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…


Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.