
EvilOSX
An evil RAT (Remote Administration Tool) for macOS / OS X.

An evil RAT (Remote Administration Tool) for macOS / OS X.

Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.

SSHPry v2 - Spy & Control os SSH Connected client's TTY

PHP shells that work on Linux OS, macOS, and Windows OS.

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Mac OS Trojan (RAT) made with love <3

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

Authenticated Blind OS Command Injection in ClearOS

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

📦 Make security testing of K8s, Docker, and Containerd easier.

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

PoC and vulnerability report for CVE-2025-47827.

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386