
watermarks-remover
Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Evasion kit for Cobalt Strike


Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

A new simple and powerfull packer for malware

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…

macOS Initial Access Payload Generator

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Collection of offensive techniques for attacking Windows environments, with practical methods for exploitation, privilege escalation, and adversarial…

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

This repository provides the official implementation of POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models.

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control,…

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

Proof-of-concept exploit for CVE-2026-44578 that reproduces the vulnerable condition, enabling security researchers to validate affected systems and…

Windows Defender patch bypass PoC for CVE-2026-50656 (RoguePlanet), demonstrating exploitability on Windows 11 25H2 and Server 2025 despite…

Sample code for DNS spoofing with ARP poisoning.