
blackbox-pentesting-infsecos
Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

A super portable botnet framework with a Django-based C2 server. The client is written in C++, with alternate clients written in Rust, Bash, and…

Living Under the Land on Linux ~ Bsides Belfast/Vienna 2025

Stealth Kid RAT (SKR) is an open-source multi-platform Remote Access Trojan (RAT) written in C#. Released under MIT license. The SKR project is fully…

Code Roulette is a terminal interface based (TUI), online multiplayer, Russian Roulette game where the loser executes the winner's Python payload…

Educational repository detailing the Shellshock (CVE-2014-6271) vulnerability, including technical analysis, attack vectors, proof-of-concept…

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

The code for personally reproducing the corresponding vulnerability

Proof-of-concept exploit for CVE-2025-68613, a critical RCE vulnerability in n8n workflow automation via expression injection in the executeCommand…

Exploit for the CVE-2025-37164

Python-based exploit for CVE-2024-10915, a command injection vulnerability in D-Link NAS devices. Executes arbitrary system commands via the…

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server

Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.