
CVE-2022-30190-follina-Office-MSDT-Fixed
Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

macOS Initial Access Payload Generator

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

XLL Phishing Tradecraft

transform your payload.exe into one fake word doc (.ppt)

Use a Fake image.jpg to exploit targets (hide known file extensions)

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

JShell - Get a JavaScript shell with XSS.

Embed and hide any file in an HTML file

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

The SteaLinG is an open-source penetration testing framework designed for social engineering

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC