
CVE-2024-34102
Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Proof-of-concept exploit for CVE-2026-41653, a stored XSS in BentoPDF that enables silent file exfiltration and WASM supply-chain hijacking.

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

The CIA Hive source code as released by Wikileaks

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

Updated version of PowerDNS by @domchell. Adds support for transfers over DNS A records and a few other useful features.

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration…

Cobalt Strike BOF that creates an LSASS minidump in memory and exfiltrates it over the C2 callback for offline credential parsing with Mimikatz or…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

Embed a payload inside a PNG file

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.