
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)

My experiments in weaponizing Nim (https://nim-lang.org/)

Rust Weaponization for Red Team Engagements.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

a guard that blocks catastrophic agent actions

Automatic SSTI detection tool with interactive interface

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

To reproduce CVE-2021-31630

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

.NET/PowerShell/VBA Offensive Security Obfuscator

CVE-2022-1292 OpenSSL c_rehash Vulnerability

Weblogic CVE-2020-14882 unauthorized RCE exploit with patch bypass, command execution, and webshell deployment for penetration testing.

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2025-53652: Jenkins Git Parameter Analysis

CImg Library v.2.3.3 - command injection