
FortiSandbox-RCE-Exploit-CVE-2026-39808
Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

This is a concept poc of command and control server implemented over blockchain

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

Script is a proof of concept how to control your machine by using social media sites.

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs


This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

CVE-2025-57174 Unauthenticated Remote Command Execution

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Presents how to exploit CVE-2021-44228 vulnerability.