
javascript-deobfuscator
Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

0-day malware detection for binaries, source & scripts (that doesn't suck)

frida-stalker based system call tracer on windows(x64).

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Proof-of-concept demonstrating CVE-2023-38831, a WinRAR path traversal vulnerability, by crafting a malicious ZIP archive that executes arbitrary…

C++ implementation of CVE-2025-8088 WinRAR exploit using Alternate Data Streams to drop payloads into Windows Startup folder for persistence.

Exploit For: CVE-2024-42845: Remote Code Execution (RCE) in Invesalius 3.1

OS Command Injection Vulnerability via Cache Clearing Scheduler in Reolink Desktop Application

A POC exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Proof-of-concept exploit for Microsoft Office security feature bypass (CVE-2026-21509). Generates malicious DOCX files with embedded OLE objects to…

Proof-of-concept for CVE-2026-2441, a use-after-free in Chrome's CSS engine, demonstrating renderer crash and potential sandboxed code execution via…

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Exploit for CVE-2026-21509, a Microsoft Office OLE validation bypass using a speculative race-condition technique to evade AMSI/EDR and achieve code…