
CVE-2026-60004-POC
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Proof-of-concept exploit for CVE-2024-21006 targeting Oracle WebLogic Server via T3/IIOP, enabling unauthenticated remote access to critical data.

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

CVE-2026-12415-or-CVE-2026-12416.py

CVE-2020-2551 Exploiter

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

PoCs and tools for investigation of Windows process execution techniques

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Tools and PoCs for Windows syscall investigation.

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Attempt at Obfuscated version of SharpCollection

A PoC ransomware sample to test out your ransomware response strategy.

Adversary Emulation Framework

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.