
SocialFish
Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Living Under the Land on Linux ~ Bsides Belfast/Vienna 2025

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Step-by-step walkthrough exploiting CVE-2023-30258 (MagnusBilling RCE) and escalating privileges via fail2ban misconfiguration on a TryHackMe lab.…

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

Python exploit for CVE-2018-7600 (Drupalgeddon 2) enabling remote code execution on Drupal 7 with multiple injection methods and predefined commands…

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

Stealth Kid RAT (SKR) is an open-source multi-platform Remote Access Trojan (RAT) written in C#. Released under MIT license. The SKR project is fully…

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

Demonstration of Windows MSDT Vulnerability (CVE-2022-30190)

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…