
SCMKit
Source Code Management Attack Toolkit

Source Code Management Attack Toolkit

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Source Code Management Attack Toolkit

POCs to demonstrate CVE-2026-42167 in ProFTPD

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

An implementation of a vulnerable MCP server using mcp-go

WordPress Privilege Escalation Checker

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

This simple bash script will patch the recently discovered sudo heap overflow vulnerability.

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

Macally WIFISD2

Burp plugin which supports in finding privilege escalation vulnerabilities

The Shadow Attack Framework

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.


Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

Local privilege escalation via PetitPotam (Abusing impersonate privileges).