
BadOutlook
Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

How to spoof the command line when spawning a new process from C#.

CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing…

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Tool to check if an IP of a DblTek GoIP is vulnerable to a challenge-response login system, send SMS messages from the system, execute remote…

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.…

This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Private x64 RCE exploit for CVE-2024-6387 [02.07.2024] from exploit.in

Remote Command Execution into shell from a vulnerable exim service.