
CVE-2026-65400
Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A basic emulation of an "RPC Backdoor"

Various ways to execute shellcode

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)


A third-party Gopher Assassin for the Havoc Framework.

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

Documents Exfiltration project for fun and educational purposes

Source generator to add D/Invoke and indirect syscall methods to a C# project.


IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

Leverage WindowsApp createdump tool to obtain an lsass dump

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Terminate AV/EDR leveraging BYOVD attack

A Rust template for writing Beacon Object Files (BOFs)