
thc-tips-tricks-hacks-cheat-sheet
Various tips & tricks

Various tips & tricks

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

A collection of selenium tests that might aid it takeover of a selenium node

Analysis of malware found on a server compromised via CVE-2025-55182, including obfuscated dropper, C2 communication, persistence mechanisms, and…

React2Shell Exploitation Tool (CVE-2025-55182)

Adversary Emulation Framework

Decrypted content of eqgrp-auction-file.tar.xz

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A collaborative, multi-platform, red teaming framework

My experiments in weaponizing Nim (https://nim-lang.org/)

Windows Remote-Access-Trojan

PCShare是一款强大的远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。

Remote Access Trojan(RAT), Miner, DDoS

Embed a payload inside a PNG file