
wraith
Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

CVE-2025-32433-available-for-windows-victims

A collection of selenium tests that might aid it takeover of a selenium node

使用burp自动检测CVE-2025-55182 Next.js RCE 漏洞

Android remote administration tool

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Exploit for CVE-2025-53770, a SharePoint ViewState deserialization vulnerability, enabling remote code execution via crafted payloads.

Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability

A PoC for CVE-2025-24813

Automated Python exploit for CVE-2023-30258, a command injection in Magnus Billing System v7. Sends crafted GET request to icepay.php to execute…

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

Proof-of-concept exploit for CVE-2024-29973, a command injection vulnerability in Zyxel NAS devices. Executes arbitrary OS commands via a crafted…

Proof-of-concept exploitation steps for CVE-2024-3400, demonstrating unauthenticated command injection in Palo Alto GlobalProtect via crafted cookie…