
dropengine
DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。

This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerabilit…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Python-Based Pentesting CLI Tool

Exploitation toolkit for RichFaces

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…


Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

A cross-platform C2/teamserver supporting multiple transport protocols, written in Go.

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Proof-of-concept exploit for CVE-2022-30333 path traversal in unRAR, generating malicious .rar files to plant payloads at arbitrary locations.…

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is…

Metasploit module and Python script to generate SWF payloads exploiting CVE-2018-15982, a use-after-free vulnerability in Adobe Flash Player enabling…

Exploit Generator for CVE-2018-8174 & CVE-2019-0768 (RCE via VBScript Execution in IE11)

An attempt to reproduce Microsoft MSHTML Remote Code Execution (RCE) Vulnerability and using Metasploit Framework.

Proof-of-concept exploit for a heap buffer overflow in libpng on PS4/PS5. Generates a malicious PNG that triggers the vulnerability when opened in…