
Kitsune
Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

weaponized tool for CVE-2020-17144

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Exploit for CVE-2022-46169

Small backdoor using cookie.

A Windows Remote Administration Tool in Visual Basic with UNC paths

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injection through the Webmin's File Manager feature

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injetion through the Webmin's Upload and Download feature

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Command Injection through the Webmin's File Manager feature

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Command Injection through the Webmin's Upload and Download feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)