
dicerosbicornis
A fully featured Windows backdoor that uses email as a C&C server

A fully featured Windows backdoor that uses email as a C&C server

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

C&C Botnet written in Python with fabric

Ping Exfiltration Command and Control (PiX-C2)

xll windows reverse shell

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

Authenticated RCE exploit for SuiteCRM <= 8.0.1 via email template image upload, planting a PHP webshell for remote command execution.

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Proofpoint Email Gateway: Low level authenticated user to admin RCE

CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook

Tools and Techniques for Red Team / Penetration Testing

Microsoft-Outlook-Remote-Code-Execution-Vulnerability