
peeko
peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

PoC for CVE-2023-28771 based on Rapid7's excellent writeup

A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Exploit based in /jaiguptanick/CVE-2019-0232

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105

Expanded Exploit based on CVE-2024-41570

complex webshell manager, quasi-http botnet.


Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

Remote code execution exploit for Drupal CVE-2018-7600 (Drupalgeddon2) with command injection via HTTP requests.

RCE exploit for ProxyLogon vulnerability in Microsoft Exchange

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

MS-MSDT Follina CVE-2022-30190 PoC document generator