
ghostsplice
Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are…

Adversary Emulation Framework

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

exploitdb // The official Exploit-Database repository

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

SambaCry exploit and vulnerable container (CVE-2017-7494)