
CVE-2025-5548
Step-by-step binary exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow) with Ghidra, Immunity Debugger, and Python PoC…

Step-by-step binary exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow) with Ghidra, Immunity Debugger, and Python PoC…

indirect syscalls for AV/EDR evasion in Go assembly

A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.

Proof-of-concept exploit for CVE-2023-34362, abusing SQL injection to obtain a sysadmin API token and deserialization for remote code execution on…

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Proof-of-concept exploit chaining four CVEs (CVE-2023-36844-47) for pre-authentication remote code execution on Juniper JunOS SRX and EX series…

Detailed analysis and exploit for a remote code execution vulnerability (CVE-2024-38366) in the CocoaPods Trunk Server, enabling OS command injection…

Metasploit module for CVE-2023-6710 stored XSS exploitation targeting mod_cluster, with PoC and installation guide for ethical penetration testing.

ICMP-based command and control server/client for covert remote command execution via ping packet payloads. Includes Python and PowerShell clients for…

Proof-of-concept exploit for CVE-2025-32756, demonstrating deep exploitation techniques for vulnerability analysis and penetration testing.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

CTF framework and exploit development library

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Tools and Techniques for Red Team / Penetration Testing

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Automated backdoor and payload generator that compiles cross-platform malware with AV evasion, leveraging MSFvenom and Metasploit for…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…