
Crystal-Kit
Evasion kit for Cobalt Strike

Evasion kit for Cobalt Strike

Call stack spoofing for Rust


C++ self-Injecting dropper based on various EDR evasion techniques.

Amsi Bypass payload that works on Windwos 11

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Improved version of EKKO by @5pider that Encrypts only Image Sections

Crystal Palace library for proxying Nt API calls via the Threadpool

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Go-based scanner that detects SharePoint CVE-2025-53770 RCE vulnerability by injecting a harmless marker into the ToolBox widget and verifying its…

Proof-of-concept exploit for CVE-2026-25253, demonstrating one-click RCE on OpenClaw via Cross-Site WebSocket Hijacking. Includes attacker server and…

Python-based exploit module targeting CVE-2026-10520 with automated payload delivery and vulnerability verification for penetration testing…

In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

PoC toolkit for exploiting Cisco IMC RCE CVE-2026-20200

Exploit for CVE-2023-36845, a PHP environment variable manipulation vulnerability in Juniper SRX/EX, enabling unauthenticated remote code execution…

how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP