
Decepticon
Autonomous Hacking Agent for Red Team

Autonomous Hacking Agent for Red Team

A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…


Kali365 - EvilTokens Replica

Proof-of-concept demonstrating command injection vulnerabilities in Composer's Perforce driver, with two attack vectors and Docker-based testing.


exploit for CVE-2026-42945

Explorations of CVE-2024-49368 + Exploit Development

Spring Boot Log4j - CVE-2021-44228 Docker Lab

Python proof-of-concept for Apache Spark Shell Command Injection (CVE-2022-33891), featuring sleep-based detection, interactive command execution,…

Apache Spark Shell Command Injection Vulnerability

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

A Rust template for writing Beacon Object Files (BOFs)

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Covenant is a collaborative .NET C2 framework for red teamers.