
CVE-2026-32202
Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for…

Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for…

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

A script to automate keystrokes through a graphical desktop program.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

Phishing with a fake reCAPTCHA

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…