
BadSamba
This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Proof-of-concept exploit for CVE-2018-20250, a remote code execution vulnerability in WinRAR's ACE file extraction, enabling arbitrary file write to…

Unauthenticated Blind Command injection in the enable_user function of DroboAccess v 2.1

Open source templates you can use to bootstrap your security programs

PoC that triggers Windows WebClient startup through EFS RPC call chains and WNF messages, enabling red teams to explore unprivileged service-start…

Python exploit script for CVE-2018-20250 that generates a malicious RAR archive to achieve code execution via WinRAR's ACE file extraction…

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

Automated exploit script for CVE-2018-20250 (WinRAR ACE extraction code execution) that generates a malicious archive file embedding a payload into…

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

PoC exploit for CVE-2025-59536, a high-severity code injection vulnerability in Claude Code's startup trust dialog, enabling remote exploitation of…

C# toolkit for establishing and managing Windows persistence via registry keys, scheduled tasks, services, startup folders, KeePass configs, and…

CVE-2021-42559: Command Injection via Configurations in MITRE Caldera

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…