
the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex
PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

A delicious, but malicious SSL-VPN server 🌮

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Modern PIC implant for Windows (64 & 32 bit)

Inject DLLs into the explorer process using icons

Threadless Process Injection using remote function hooking.

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Encrypts .NET executables with a polymorphic stub, junk-code flooding, and entry-point proxy to protect malware payloads from static detection.

A payload delivery system which embeds payloads in an executable's icon file!

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

Windows kernel-mode COFF loader for executing x64 kernel COFF payloads, supports NTOSKRNL/SSDT imports and client-driven loading for red-team…

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…