
AlanFramework
A C2 post-exploitation framework

A C2 post-exploitation framework

Proof-of-concept for CVE-2025-54100: XSS in PowerShell's Invoke-WebRequest via mshtml.HTMLDocumentClass, enabling remote code execution when curling…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Damn easy multiplatform Node.js RAT generator.

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

JavaScript for Automation (JXA) macOS agent

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

Serverless AITM Simulation Framework for Entra ID and M365

Python exploit script for CVE-2024-25180, a remote code execution vulnerability in pdfmake, delivering a reverse shell via crafted POST requests.

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

BrowserBackdoor is an Electron Application with a JavaScript WebSocket Backdoor and a Ruby Command-Line Listener

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Payload Generation Framework

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain