
CVE-2022-30190
Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

Proof-of-concept exploit for Windows Notepad markdown engine RCE, generating a malicious markdown file that triggers payload delivery via WebDAV/SMB…

A tool to transform Chromium browsers into a C2 Implant

Generates malicious Office for Mac macros with beacon, credential harvesting, and meterpreter payloads for phishing and exploitation testing on macOS.

Authenticated RCE exploit for WonderCMS v3.2.0–v3.4.2 using reflected XSS to upload a reverse shell via theme/plugin installation.

Proof-of-concept exploit for CVE-2023-23397 that crafts malicious Outlook emails to leak Net-NTLMv2 hashes via UNC path in…

C-based XLL payload development for phishing campaigns, with techniques for delivery via ZIP containers, self-deletion, and evasion of AV/EDR and…

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Encodes binary implants into HTML files for phishing delivery, decoding and dropping the payload when the target opens the file. Supports custom…

Windows active user credential phishing tool

Social engineering toolkit for bulk phishing campaigns with macro-based payload generation, email tracking, and automated agent deployment for…