
Cheshire
Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)

A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase"…

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

Metasploit modules and payload generation files from my Houston Perl Mongers talk about this vulnerability.

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over…

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

A collection of selenium tests that might aid it takeover of a selenium node

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.