
XLL_Phishing
XLL Phishing Tradecraft

XLL Phishing Tradecraft

CVE-2023-6401 is a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a malicious `dbghelp.dll` file in the…

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

A fully featured backdoor that uses Twitter as a C&C server

We developed GRAT2 Command & Control (C2) project for learning purpose.

A PoC project for embedding shellcode to Hint/Name Table


CVE-2022-39197 RCE POC


Automatic UAC-Bypassing for custom payloads during privilege escalation testing

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

The Browser Exploitation Framework Project

This is a webshell open source project