

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Automated phishing simulation tool with 30+ login page templates, URL masking, and multiple tunneling options (Ngrok, Cloudflared, Serveo) for…

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

Security awareness training tool for authorized phishing simulations and internal IT audits

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Proof of concept for CVE-2024-37383

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC)…

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

Proof-of-concept exploit for stored XSS vulnerability in VanillaForum 2.6.3, demonstrating arbitrary HTML/script injection via insufficient input…

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload