
CVE-2026-6875-PoC-Exploit
CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

A tool to transform Chromium browsers into a C2 Implant

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Mac OS X rootkit - for learning purposes

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Permanently disable EDRs as local admin

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

LSTAR - CobaltStrike Translated to EN

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.


PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

njRAT C# Stub - Fixed For PowerShell

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…