
CVE-RUBY
Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Various ways to execute shellcode

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development


Tools and PoCs for Windows syscall investigation.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

C++ self-Injecting dropper based on various EDR evasion techniques.

Source generator to add D/Invoke and indirect syscall methods to a C# project.

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits