
Heroinn
A cross platform C2/post-exploitation framework.

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…