
Supershell
Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

A script to automate keystrokes through a graphical desktop program.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

Phishing with a fake reCAPTCHA

A exploit for the CVE-2019-11395 vulnerability in the MailCarrier 2.51 email application, enabling remote code execution.

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.