
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

More examples using the Impacket library designed for learning purposes.

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).

A short demo of CVE-2021-44228

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Proof-of-concept exploit for CVE-2021-43609 demonstrating SQL injection to file read to remote code execution chain against Spiceworks help desk…

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC