
mcpExec
POC for CVE-2026-23744 for a python revshell

POC for CVE-2026-23744 for a python revshell
Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646)

A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server…

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

An All-In-One Pure Python PoC for CVE-2021-44228

C&C Botnet written in Python with fabric

An open-source Linux GUI-based Remote Access Tool developed in C# with a Python payload, intended for legitimate penetration testing and…

Python exploit for Metabase pre-authentication remote code execution (CVE-2023-38646) with setup-token extraction and collaborator callback for…

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info


ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability

Python script to detect CVE-2022-30525 OS command injection vulnerability in Zyxel USG FLEX devices by sending crafted HTTP requests and analyzing…