
ibombshell
Tool to deploy a post-exploitation prompt at any time

Tool to deploy a post-exploitation prompt at any time

This is the exploit of CVE-2019-17240.

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

:dart: Prevent RubberDucky (or other keystroke injection) attacks

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

I have documented all of the AMSI patches that I learned till now

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Passive Security Tools Fingerprinting Framework