
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)

My experiments in weaponizing Nim (https://nim-lang.org/)

Rust Weaponization for Red Team Engagements.

Automatic SSTI detection tool with interactive interface

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

.NET/PowerShell/VBA Offensive Security Obfuscator

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

a guard that blocks catastrophic agent actions

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

CVE-2020–14882、CVE-2020–14883

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

CVE-2022-1292 OpenSSL c_rehash Vulnerability

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

CVE-2025-53652: Jenkins Git Parameter Analysis

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CImg Library v.2.3.3 - command injection

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…