
tools
Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

remote code execute for redis4 and redis5

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

PoC and analysis for CVE-2022-26809, a Windows RPC runtime integer overflow vulnerability. Includes trigger scripts using PetitPotam-style UNC path…

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Post-exploitation framework that abuses trusted sites like Telegram and Discord for C2.

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

Displays an old-school crack-intro animation on compromised Canon and Lexmark printers, with SDL2 and WebAssembly builds for portability and study.

Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)

A C# PE loader for x64 and x86 PE files.

Patches and hooks the Linux kernel using only a stripped kernel image, extracting symbols and injecting code for inline and syscall hooking on arm64.

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

Full-chain Chrome exploit targeting CVE-2019-5782 and CVE-2019-13768 with custom ROP gadgets and shellcode for arbitrary command execution on Windows…