
HTB-TwoMillion-Writeup
HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386


Autonomous Hacking Agent for Red Team

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…


EXOCET - AV-evading, undetectable, payload delivery tool

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

A simple C2 Framework written in modern C++

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…