
DCVC2
Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Single-file Python scanner and exploit for CVE-2026-85706, an unauthenticated arbitrary file read in self-managed GitLab CE/EE, with project…

Exploiting Android Vulnerability in ES File Explorer

Bash PoC script exploiting CVE-2019-6447 in ES File Explorer to list files, photos, videos, apps, and download files from vulnerable Android devices.

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

CVE-2024-0044: uma vulnerabilidade de alta gravidade do tipo "executar como qualquer aplicativo" que afeta as versões 12 e 13 do Android

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

File Injector is a script that allows you to store any file in an image using steganography

Parses Snaffler output file and generate beautified outputs.

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Transparent file encryption in git

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

Netcat with automated NAT traversal, secure P2P, and advanced features for shell access, file transfer, and network proxying.

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

Go exploit for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE Workhorse via URL-encoding bypass, with concurrent requests and…

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

Python PoC exploiting CVE-2026-85706, an unauthenticated path traversal and arbitrary file read in GitLab CE/EE via the create-commit endpoint, with…