
lscript
The LAZY script will make your life easier, and of course faster.

Payload Generation Framework

An XSS exploitation command-line interface and payload generator.

Self contained htaccess shells and attacks

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Embed and hide any file in an HTML file

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

XLL Phishing Tradecraft

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

CVE-2022-30190-follina.py-修改版,可以自定义word模板,方便实战中钓鱼使用。

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

Write-up for another forgotten Windows vulnerability (0day): Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape,…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

This is a proof-of-work for abusing "fsmonitor" against IDE.

CVE-2022-30190 | MS-MSDT Follina One Click