
chromium-exploit-dev
Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Image Payload Creating/Injecting tools

Win32 and Kernel abusing techniques for pentesters

Mythic C2 agent targeting Linux and Windows hosts written in Rust

C++ library that retrieves and spoofs Windows syscall arguments using hardware breakpoints and exception handlers to subvert EDR telemetry.

PoC for triggering buffer overflow via CVE-2020-0796

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

CVE-2017-7269 to webshell or shellcode loader

Git Web Hook Tunnel for C2

exp for CVE-2019-0887

Proof of concept python script for regreSSHion exploit.

Atlassian Jira unauthen template injection

Windows SmartScreen Security Feature Bypass Vulnerability