


Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

The Shadow Attack Framework

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

A tool for security professionals to access and interact with remote Microsoft Windows based systems.

Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…


🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

Microsoft Office Word Rce 复现(CVE-2022-30190)

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

Python based tool for generating Shellcode from PIC C

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

CVE-2026-50522 PoC