
SignHere
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

Windows research PoC in C that scans Microsoft Edge process memory for credential-related data, with a standalone executable and a BOF variant for C2…

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

Malicious Register Directive Code Injection Exploit

Proof of concept demonstrating command execution in Microsoft Notepad via crafted files, enabling arbitrary code execution and system compromise.

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…

MS-MSDT Follina CVE-2022-30190 PoC document generator

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Cobalt Strike HTTPS beaconing over Microsoft Graph API

A native backdoor module for Microsoft IIS (Internet Information Services)

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Proof-of-concept exploit for CVE-2022-41080 (OWASSRF) enabling remote code execution through Microsoft Exchange Outlook Web Access, bypassing…

CVE-2022-41082-poc

Proof of Concept of CVE-2022-30190