
FakeImageExploiter
Use a Fake image.jpg to exploit targets (hide known file extensions)

Use a Fake image.jpg to exploit targets (hide known file extensions)

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

Automated JavaScript shell generator for XSS exploitation. Generates a payload and delivers a JS shell over netcat to execute arbitrary code in the…

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Encrypts and embeds any file into an HTML page with automatic decryption and download simulation for social engineering and payload delivery.

C-based XLL payload development for phishing campaigns, with techniques for delivery via ZIP containers, self-deletion, and evasion of AV/EDR and…

Scripts for generating Office macro payloads to deliver executables and PowerShell commands, aiding in red team engagements and phishing simulations.

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook RCE vulnerability, demonstrating email-based attack with configurable templates and…

Generate C2 payloads embedded in favicon files, executed via PowerShell for covert command-and-control operations.

CLI for rapidly deploying, managing, and tearing down ephemeral cloud-based penetration testing infrastructure, including VMs, C2 servers, domain…

Automated framework for CVE-2023-38831 exploitation with payload generation, email delivery, and download link creation for social engineering…

Generates malicious RTF documents exploiting CVE-2017-11882 to execute arbitrary commands or payloads via embedded Equation objects and VBScript.

Proof-of-concept exploit for CVE-2025-1015 demonstrating unsanitized URI fields in Thunderbird Address Book leading to unprivileged JavaScript…

Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…