
Salsa-tools
Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

Exploit for CVE-2025-64512 to get a reverse shell.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Using CVE-2021-40449 to manual map kernel mode driver

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

PHPMailer < 5.2.18 Remote Code Execution Exploit

Exploit for Ivanti Automation Manager CVE-2022-44569

PoC for CVE-2020-8165

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

A collection of selenium tests that might aid it takeover of a selenium node

Presents how to exploit CVE-2021-44228 vulnerability.

Proof-of-concept exploit demonstrating remote command execution in Go's `go get` via crafted cflags in a malicious third-party package.

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

Proof-of-concept exploit for CVE-2021-38666, a Windows Remote Code Execution vulnerability. Demonstrates exploitation techniques for security testing…

Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes