
CVE-2026-8037-POC
包括能执行的命令探测和一键getshell(需要服务器部署服务)

包括能执行的命令探测和一键getshell(需要服务器部署服务)

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

CVE-2025-33073

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

MeshDeck port for Arch Linux ARM - Wilson

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

Dominate Active Directory with PowerShell.

A framework for constructing self-spreading binaries

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

D(COM) V(ulnerability) S(canner) AKA Devious swiss army knife - Lateral movement using DCOM Objects

Fully modular persistence framework

DCOM in memory and fileless lateral movement techniques through .Net deserilization

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Open Source C&C Specification

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

VMware Aria Operations for Logs CVE-2023-34051

BOF POC of the DSCourier project / invoking WinGet via COM