
WAREED-DNS-C2
DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

Generate a proxy dll for arbitrary dll

Generate Proxy DLLs in Rust

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

GUI-based exploit tool for CVE-2020-14882 targeting Oracle WebLogic servers. Supports reverse shell payload generation, proxy configuration, and…

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

Exploit for CVE-2021-21972 targeting VMware vCenter with options for webshell or SSH key upload, proxy support, and batch scanning.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Powershell C2 Server and Implants

Proof-of-concept exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence. Executes a JavaScript payload against…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Automated scanner for CVE-2026-6271, a critical unauthenticated arbitrary file upload leading to RCE in the WordPress Career Section plugin. Supports…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Drupal CVE-2018-7600 RCE Pseudo-Shell PoC


Proof-of-concept exploit for unauthenticated remote code execution in Tatsu Builder WordPress plugin (CVE-2021-25094). Supports multiple shell…

Authenticated remote code execution exploit for Cacti graph template vulnerability, with reverse shell payload and proxy support for authorized…