
CVE-2022-30190
Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

Tools and Techniques for Red Team / Penetration Testing

PoC for the "Windows Notepad RCE"

A tool to transform Chromium browsers into a C2 Implant

Generates malicious Office for Mac macros with beacon, credential harvesting, and meterpreter payloads for phishing and exploitation testing on macOS.

WonderCMS Authenticated RCE - CVE-2023-41425

XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.

CVE-2023-23397 PoC

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

XLL Phishing Tradecraft

Excel Macro Document Reader/Writer for Red Teamers & Analysts

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.


Windows active user credential phishing tool

Social Engineering Tool