
Exploits + Shellcode + GHDB
exploitdb // The official Exploit-Database repository

exploitdb // The official Exploit-Database repository

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Attempt at Obfuscated version of SharpCollection

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP

Offensive Lua.

abusing windows toast notifications for fun and user manipulation

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

PowerSploit - A PowerShell Post-Exploitation Framework

hacklib - pentesting, port scanning, and logging in anywhere with Python

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

Cisco ASA Software and ASDM Security Research

CVE-2026-63030, CVE-2026-60137, wp2shell scanner