
CVE-2025-52691-APT-PoC
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation,…

An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation,…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

ExtensionHijack

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Cobalt Strike extension for post-exploitation persistence using SharpStay .NET assembly. Provides GUI-driven persistence via Registry keys, Scheduled…

Xenotix Python Keylogger for Windows.

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.