
IIS-Raid
A native backdoor module for Microsoft IIS (Internet Information Services)

A native backdoor module for Microsoft IIS (Internet Information Services)

Small PoC to automate exploitation of CVE-2025-63406.

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

Small backdoor using cookie.

Exploiting Parsec for Windows to gain SYSTEM privileges

Unauthenticated RCE exploit for Veritas Backup Exec Agent (CVE-2021-27876/77/78) — SHA auth bypass to SYSTEM via NDMP

Documented incident response case for CVE-2024-49138 exploitation, featuring log analysis, hash validation, C2 detection, and containment procedures…

Automated Mass Exploiter

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

A small reverse shell for Linux & Windows

Small PHP shell, Controlled by Python Client , connecting over protocol method

Reproduction of CVE-2022-39197, a remote code execution vulnerability in Cobalt Strike Beacon triggered by XSS via malformed usernames, with…