
n00bRAT
Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command…

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

A proof-of-concept Command & Control framework that utilizes the powerful AsyncSSH Python library which provides an asynchronous client and server…


Windows Remote Access Trojan (RAT)

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

exploit for CVE-2026-42945

A simple C2 Framework written in modern C++

Spring Boot Log4j - CVE-2021-44228 Docker Lab

Proof-of-concept exploit for CVE-2023-34992 enabling unauthenticated blind command injection as root on vulnerable Fortinet FortiSIEM appliances.

CVE-2022-1292 OpenSSL c_rehash Vulnerability - POC

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection

Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…