
CVE-2024-10914
CVE-2024-10914_Manual testing with burpsuite

CVE-2024-10914_Manual testing with burpsuite
Hunts out CobaltStrike beacons and logs operator command output

A PoC Java Stager which can download, compile, and execute a Java file in memory.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Apfell C2 Server for the Google Chrome Extension Payload

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

Automated exploit for Chamilo command injection vulnerability (CVE-2023-34960) with auto shell upload capability for penetration testing and…

A Proof of Concept for the CVE-2021-27928 flaw exploitation

Automatic SSTI detection tool with interactive interface

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

Apache OFBiz unsafe deserialization of XMLRPC arguments

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

ICMP-based command-and-control tool that tunnels C2 traffic through firewalls using ping payloads, undetectable by most AV/EDR solutions.