
khaos-c2
KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

C# Reflective loader for unmanaged binaries.

Lateral Movement Using DCOM and DLL Hijacking

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Local & remote Windows DLL Proxying

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

CVE-2021-42287/CVE-2021-42278 exploits in powershell

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

CVE-2026-28289

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…