
DragonCastle
A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A backdoor with a multitude of features.



Open-Source Remote Administration Tool For Windows C# (RAT)

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

POC - CVE-2024–24919 - Check Point Security Gateways

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

Python Remote Administration Tool (RAT)

Tool to remotely dump secrets from the Windows registry


iOS/macOS/Linux Remote Administration Tool

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)


From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

A little tool to play with Windows security

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…