
cloudrasp-log4j2
一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Fawkes is a golang Mythic C2 Agent exclusively written by AI.


Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

The Correlated CVE Vulnerability And Threat Intelligence Database API

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

Virtual Machine for Adversary Emulation and Threat Hunting

ARM64 ELF Virtual Machine Protection System

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

BOF combination of KillDefender and Backstab


Proof-of-concept exploit for CVE-2023-29336, a Win32k elevation of privilege vulnerability enabling SYSTEM-level access on affected Windows systems.