
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298
SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

A tool to transform Chromium browsers into a C2 Implant

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

A collection of tools for dealing with TrickBot

CVE-2025-33053 Proof Of Concept (PoC)

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Serverless AITM Simulation Framework for Entra ID and M365