
XSStrike
Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Micro lab for CVE-2021-44228 (Log4Shell) with automated multi-target exploitation, runtime payload generation, and adjustable bypasses for security…

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

Dockerized Spring4Shell (CVE-2022-22965) proof-of-concept with Python exploit script and webshell deployment for educational vulnerability testing.

In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

Java agent that intercepts CVE-2022-42889 (Text4Shell) exploitation attempts via JVM startup parameters or JPS PID injection, with runtime detection…

Automatic SSTI detection tool with interactive interface

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

.NET command and control framework with dynamic C# compilation, encrypted key exchange, and multi-user collaboration for red team operations.…

In-memory Java stager that downloads, compiles, and executes arbitrary Java payloads over HTTP, enabling AV evasion and remote code execution for red…