
javascript-obfuscator
Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

Penetration tests guide based on OWASP including test cases, resources and examples.

EXOCET - AV-evading, undetectable, payload delivery tool

Embed a payload inside a PNG file

A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs.

A new simple and powerfull packer for malware

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

Lightweight library which allows the ability to map both native and managed assemblies into memory by either using process injection of a process…

Reference implementation of a multi-bit LLM watermarking scheme using coded payload spreading, unbiased reweighting, and soft-decision ECC decoding…

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…


Red Team Coin for crypto-mining operations.

Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

CurveBall CVE exploitation

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit