
GhostTunnel
Covert backdoor transmission tool using 802.11 probe request and beacon frames for isolated network attacks. Delivers payloads via HID devices,…

Covert backdoor transmission tool using 802.11 probe request and beacon frames for isolated network attacks. Delivers payloads via HID devices,…

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

CVE-2025-53547 one of poc code

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Windows SmartScreen Security Feature Bypass Vulnerability

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Python-based proof-of-concept exploit for CVE-2024-7399 with check, command execution, and file upload capabilities against HTTPS endpoints.

In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses…

A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

A Python 3 script that uploads a tasks.pickle file that enables RCE in MotionEye. CVE-2021-44255

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

A webshell framework for penetration testers.

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…