
CVE-2025-50505
Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

C# Reflective loader for unmanaged binaries.

Tools and Techniques for Red Team / Penetration Testing

CVE-2025-33073

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Create fake certs for binaries using windows binaries and the power of bat files

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

Penetration testing framework with AI-driven decision engine

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

BOF POC of the DSCourier project / invoking WinGet via COM

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Lateral Movement Using DCOM and DLL Hijacking

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

Fully modular persistence framework

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.