
Kage
Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

CVE-2025-55182 — Unauthenticated RCE in React Server Components (React2Shell). CVSS 10.0 exploit tool for authorized penetration testing.

A tool for generating reverse shell payloads on the fly.

CVE-2023-34468 - Apache NiFi H2 RCE PoC

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

EXOCET - AV-evading, undetectable, payload delivery tool

Avoidz tool to bypass most A.V softwares


A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

This is a custom ASCII AND/SUB Encoder developed during my preparation for the legacy OSCE/CTP course

CVE-2025-10230 PoC - Samba WINS Hook Command Injection

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

C# RAT (Remote Administration Tool)

Automated local privilege escalation exploit for CVE-2024-48990 (needrestart v3.7), leveraging PYTHONPATH hijacking to gain root access.

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…