
SharpSploitConsole
C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

DDoor - cross platform backdoor using dns txt records

a CLI for ephemeral penetration testing

Generates malicious Apache Parquet files to test for CVE-2025-30065 RCE vulnerability via SSRF callback. Designed for authorized security testing of…

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

Open Web Analytics 1.7.3 - Remote Code Execution

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Reverse engineering the "A Letter Before Court 4.docx" malicious files exploting cve-2021-40444