
CVE-2017-8759
NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Proof-of-concept exploit for CVE-2018-0802 Office Equation Editor RCE, using Packager OLE object to drop and execute embedded payloads with bypass…

A framework for constructing self-spreading binaries

Educational demonstration of CVE-2022-0847 (Dirty Pipe) Linux kernel exploit with automated compilation script for privilege escalation and file…

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

Technical analysis and proof-of-concept exploit for CVE-2025-61228, a privilege escalation vulnerability in SuperDuper!'s auto-update mechanism, with…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

This is working POC of CVE-2022-36271

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Educational PoC generating a harmless DOCX with dummy OLE artifacts to test EDR/AV visibility, ASR rules, and sandbox analysis for CVE-2026-21509.…

Proof of concept code for Datadog Security Labs referenced exploits.