
CVE-2021-21300
Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Exploit for the CVE-2024-37010: access other user's external storage & lateral movement

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…

Proof-of-concept exploit for CVE-2020-27955 in Git-LFS, demonstrating remote code execution via a crafted git clone operation to obtain a reverse…

MeshDeck port for Arch Linux ARM - Wilson

A cross platform C2/post-exploitation framework.

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

Spicy malware 0day. Full kill-chain malware: exploit, pivot, c2, persistence. Rust converted to pseudo-code - if you're smart you can build it…

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

Tool for Active Directory Certificate Services enumeration and abuse

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

A Python agent targeting Linux for Mythic C2

Modified version of the passing-the-hash tool collection made to work straight out of the box