
nah
a guard that blocks catastrophic agent actions

a guard that blocks catastrophic agent actions

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

A proof of concept demonstrating how to use the Hinge dating app as a C2.

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

CVE-2025-57174 Unauthenticated Remote Command Execution

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Presents how to exploit CVE-2021-44228 vulnerability.

How to spoof the command line when spawning a new process from C#.

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228