
CVE-2022-44877
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)

Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

A proof of concept demonstrating the use of Google Drive for command and control.

A Powershell client for dnscat2, an encrypted DNS command and control tool.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

macOS Initial Access Payload Generator

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

Android remote administration client

A basic emulation of an "RPC Backdoor"

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

PoC for jenkins 2.63 CVE-2019-1003030

Adversary Emulation Framework

A version of CVE-2017-0213 that I plan to use with an Empire stager

A PoC exploit for CVE-2022-34753 - OS Command Injection in SpaceLogic C-Bus Home Controller

Windows SmartScreen Security Feature Bypass Vulnerability

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

