
k0otkit
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Proof-of-concept exploit for CVE-2019-5736, a container escape vulnerability in runc, demonstrating the attack and enabling security testing.

Exploit CVE-2025-1974 with a single file.

CVE-2024-32462 code exec sbx escape

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

PHP poc, exploit for CVE-2025-9074

Some scripts to simulate an attack (used for CVE-2024-21626)