
CVE-2020-14882
Exploits Oracle WebLogic Server RCE (CVE-2020-14882) to execute commands on vulnerable targets, capturing output via HTTP listener.

Exploits Oracle WebLogic Server RCE (CVE-2020-14882) to execute commands on vulnerable targets, capturing output via HTTP listener.

Proof-of-concept exploit for CVE-2022-36804, a command injection vulnerability in Bitbucket Server and Data Center, enabling arbitrary code execution…

Proof-of-concept exploit for CVE-2021-29003, a remote code execution vulnerability in Genexis routers, enabling arbitrary command injection via…

Exploit for CVE-2023-36845, a PHP environment variable manipulation vulnerability in Juniper SRX/EX, enabling unauthenticated remote code execution…

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

Convert Cobalt Strike profiles to modrewrite scripts

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

C# C2 Framework centered around Stage 1 operations

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)

pinky - The PHP mini RAT (Remote Administration Tool)

Open Source Implementation of Cobalt Strike's Malleable C2


CVE-2023-20198 Exploit PoC

shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

Exploit PoC for CVE-2023-20198