
AhMyth-Android-RAT
Android Remote Administration Tool

Android Remote Administration Tool

Automatic SSTI detection tool with interactive interface

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…


A Web Vulnerability Scanner and Patcher

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Example Vulnerable .NET HTTP Remoting

a CLI for ephemeral penetration testing

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Python script to inject existing Android applications with a Meterpreter payload.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…