
CVE-2019-17564-FastJson-Gadget
Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at…

Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at…

This is a special panel that is used to send POC requests with the output of responses.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT…

ZIP Bomb Creator is a tool used to create a ZIP file that is small in size but drastically expands when extracted.

used to generate a valid attack chain to exploit CVE-2017-11774 tied to iranian apt only reasearch poc dont use for harm please

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exe2powershell - exe2bat reborn for modern Windows

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Exploitation toolkit for RichFaces

Remote Java classpath enumeration via deserialization


Open Web Analytics 1.7.3 - Remote Code Execution

CurveBall CVE exploitation

Testing CVE-2022-22968