
backcookie
PHP backdoor that receives commands via HTTP cookie, providing remote shell access to compromised web servers with custom command support.

PHP backdoor that receives commands via HTTP cookie, providing remote shell access to compromised web servers with custom command support.

Framework for building custom command-and-control protocols and integrating them with the Covenant C2 platform, enabling rapid development of…

Automated credential dumping tool with custom PowerShell payloads, in-memory execution, Mimikatz parsing, ticket dumping, and web-based dashboard for…

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

Event-driven asynchronous BOF execution framework for Cobalt Strike Beacon. Enables long-running custom event monitoring and real-time output from…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

Proof-of-concept exploit for CVE-2022-30190 (Follina) enabling remote code execution via Microsoft Support Diagnostic Tools in Office, with reverse…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

Python exploit for CVE-2024-24590 that uploads a malicious pickle file to ClearML, enabling reverse shell or custom command execution on the target…

Python-based exploit tool for CVE-2022-22947 (Spring Cloud Gateway SpEL injection). Supports single-target and batch scanning with custom command…

Python exploit for CVE-2022-25765 command injection in pdfkit, enabling remote code execution via crafted URLs with reverse shell and custom command…

Python PoC for CVE-2025-32778, exploiting command injection in Web-Check's screenshot API to execute reverse shells or custom shell commands against…

Python3 exploit for CVE-2007-2447 targeting Samba 3.0.20-3.0.25rc3 with Netcat reverse shell and custom command execution support.

Python script generating Microsoft Office documents that exploit CVE-2022-30190 for remote code execution via HTML payloads, supporting custom…

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) demonstrating remote code execution via JNDI injection with LDAP server and custom payload…