
MS-MSDT-Office-RCE-Follina
CVE-2022-30190 | MS-MSDT Follina One Click

CVE-2022-30190 | MS-MSDT Follina One Click

Script is a proof of concept how to control your machine by using social media sites.

a CLI for ephemeral penetration testing

Resources to learn more about Chinese-language cybercrime actors.

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

A proof of concept demonstrating how to use the Hinge dating app as a C2.

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

PoC CVE-2025-49144

This is a proof-of-work for abusing git's clean filter against IDEs & Sublime.

A selfbot for discord made using Discord.py. It comes with 70+ commands and server nuking features

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

PoC for CVE-2025-55319