
Striker
Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

IP obfuscator made to make a malicious ip a bit cuter

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

DNS over HTTPS targeted malware (only runs once)

A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as…

一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.

Just simple PoC for the Atlassian Jira exploit. Provides code execution for unauthorised user on a server.

Small PHP shell, Controlled by Python Client , connecting over protocol method

CMS Made Simple 2.2.7 RCE exploit

Hooked browser communication over MQTT

This is a simple POC to for show the pfsense 2.7 Command injection Vulnerability ( CVE-2023-42326)

Spring Boot Log4j - CVE-2021-44228 Docker Lab


Server to host/activate Follina payloads & generator of malicious Word documents exploiting the MS-MSDT protocol. (CVE-2022-30190)

Do you really think SharePoint is safe?