


Generates malicious Office for Mac macros with beacon, credential harvesting, and meterpreter payloads for phishing and exploitation testing on macOS.

XLL Phishing Tradecraft

Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

CVE-2025-33053 Proof Of Concept (PoC)

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

Rubber Ducky compatible clone based on CJMCU BadUSB HW.

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Hacking tools pack & backdoors generator.

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

Embed and hide any file in an HTML file