
CVE-2019-12949
CVE-2019-12949

CVE-2019-12949

XLL Phishing Tradecraft

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

Rubber Ducky compatible clone based on CJMCU BadUSB HW.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

Spoof file icons and extensions in Windows

Inject DLLs into the explorer process using icons

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

Tools for attacking Computer Use Agents

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

The Browser Exploitation Framework Project