

A fully featured Windows backdoor that uses email as a C&C server

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

Ping Exfiltration Command and Control (PiX-C2)

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Tools and Techniques for Red Team / Penetration Testing

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…


Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Proofpoint Email Gateway: Low level authenticated user to admin RCE

CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Lateral Movement Using DCOM and DLL Hijacking

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass