
PHP_8.1.x_Exploit
Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

The all-in-one browser extension for offensive security professionals 🛠

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over…

A collaborative web exploitation framework.

DDoor - cross platform backdoor using dns txt records

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Generated CVE-2026-64633 analysis payloads with treatment/control document variants and a manifest mapping IDs and pairs for reproducing the…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…


Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

Exploit for CVE-2020-5844 (Pandora FMS v7.0NG.742) - Remote Code Execution

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Reverse Shell Detection with Machine Learning

Generate an obfuscated DLL that will disable AMSI & ETW

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…