
Ninja
Open source C2 server created for stealth red team operations

Open source C2 server created for stealth red team operations

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

Exploit Apache Karaf with default credentials to deploy OSGi reverse shell payload for remote shell access.

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

Infrastructure Automation

Deploy payloads to *Nix systems en masse

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

poc for cve-2025-53772