
Tourmaline
Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

xll windows reverse shell

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

CMS Made Simple 2.2.7 RCE exploit

Use a Fake image.jpg to exploit targets (hide known file extensions)

SSHPry v2 - Spy & Control os SSH Connected client's TTY

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3