
Cobaltstrike_BOFLoader
open source port/reimplementation of the Cobalt Strike BOF Loader as is

open source port/reimplementation of the Cobalt Strike BOF Loader as is

Adversary Emulation Framework

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

A DNS rebinding attack framework.

CVE-2026-63030

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Open Source Implementation of Cobalt Strike's Malleable C2

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

This framework is designed to assist penetration testers or developers in understanding the mechanics of remote code execution (RCE) exploitation.

CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback

C PoC for CVE-2026-31431, an unprivileged Linux LPE exploiting AF_ALG page cache corruption to overwrite /usr/bin/su and gain root.