
artifacts-kit
Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

CVE-2026-22200: Arbitrary file read + CNEXT RCE in osTicket

Remote Recon and Collection

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Remote root exploit for the SAMBA CVE-2017-7494 vulnerability

Python script that generates a PNG image exploiting CVE-2022-44268 to embed and leak local file paths via ImageMagick metadata parsing.

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

This repo describes about cve-2021-29447 and a small script for exploiting automatically

Generate Seralize Payload for CVE-2019-0604 for Sharepoint 2010 SP2 .net 3.5

Step-by-step tutorial for exploiting Log4j CVE-2021-44228 with Docker-based vulnerable app, JNDIExploit listener, and LDAP payload injection for…

Curated collection of image-based payloads for authorized red-team testing and security education, with HTML examples for generating or embedding web…

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

Collection of payloads for exploiting the Log4j remote code execution vulnerability (CVE-2021-44228), including JNDI injection strings and bypass…

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

Web Backdoor Cookie Script-Kit

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…