
My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

Wiki to collect Red Team infrastructure hardening resources

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel privilege escalation, with x86_64, AArch64, and C payloads to obtain root on affected…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Collection of tools to use with Azure Applications

Proof-of-concept for CVE-2026-22008 demonstrating AWS Lambda layer injection via untrusted ARNs, enabling arbitrary code execution and credential…

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

all 4.4 ubuntu aws instances are vulnerable

A tool to transform Chromium browsers into a C2 Implant

对 CVE-2026-31431 的复现分析、C 改编的 exp。

IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation.…

My view on IngressNightmare vulnerability (CVE-2025-1974)

React2Shell Exploitation Tool (CVE-2025-55182)

Copy Fail - CVE-2026-31431

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

CocoaPods RCE Vulnerability CVE-2024-38366