
wmiexec-RegOut
Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Veil 3.1.X (Check version info in Veil at runtime)

Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

Database Driven DNS Server with a Web UI

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

A WebDAV PROPFIND C2 tool

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Arbitrary Code Execution on FuguHub 8.4

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)