
boobsnail
Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

Use a Fake image.jpg to exploit targets (hide known file extensions)

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

Automated JavaScript shell generator for XSS exploitation. Generates a payload and delivers a JS shell over netcat to execute arbitrary code in the…

Encrypts and embeds any file into an HTML page with automatic decryption and download simulation for social engineering and payload delivery.

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Scripts for generating Office macro payloads to deliver executables and PowerShell commands, aiding in red team engagements and phishing simulations.

C-based XLL payload development for phishing campaigns, with techniques for delivery via ZIP containers, self-deletion, and evasion of AV/EDR and…

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook RCE vulnerability, demonstrating email-based attack with configurable templates and…

Generate C2 payloads embedded in favicon files, executed via PowerShell for covert command-and-control operations.

CLI for rapidly deploying, managing, and tearing down ephemeral cloud-based penetration testing infrastructure, including VMs, C2 servers, domain…

Automated framework for CVE-2023-38831 exploitation with payload generation, email delivery, and download link creation for social engineering…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Generates malicious RTF documents exploiting CVE-2017-11882 to execute arbitrary commands or payloads via embedded Equation objects and VBScript.