
FortiSandbox-RCE-Exploit-CVE-2026-39808
Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

A proof of concept demonstrating how to use the Hinge dating app as a C2.

CVE-2025-57174 Unauthenticated Remote Command Execution

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Presents how to exploit CVE-2021-44228 vulnerability.

How to spoof the command line when spawning a new process from C#.

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

Demonstration of CVE-2018-19571: GitLab SSRF CVE

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…