
ShadowPhish
ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command…

ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

This repo covers some code execution and AV Evasion methods for Macros in Office documents

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC)…

PoC CVE-2025-49144

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

Proof of concept for CVE-2020-7247 for educational purposes.

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

Chamilo-LMS (v2.0) CVE-2025-26153
