
Metasploit-Module-TFM
Custom Metasploit module exploiting Kubernetes secret mount policy bypass (CVE-2023-2728, CVE-2024-3177) to retrieve secrets via crafted pods.

Custom Metasploit module exploiting Kubernetes secret mount policy bypass (CVE-2023-2728, CVE-2024-3177) to retrieve secrets via crafted pods.

Remote privilege escalation exploit for CVE-2018-1049 targeting VyOS via SSH-based command injection in a sudo-permitted Perl script, granting root…

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Pure PowerShell exploit for CVE-2021-1675 (PrintNightmare) that escalates privileges locally by adding an admin user or loading custom DLL payloads.

A standalone python script which utilizes python's built-in modules to enumerate SUID binaries, separate default binaries from custom binaries,…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Dumping LSASS with a duplicated handle from custom LSA plugin

Windows DLL proxying tool for local and remote DLL hijacking via SMB and DCOM. Generates proxy DLL payloads with custom commands, supporting Kerberos…

Automatic UAC-Bypassing for custom payloads during privilege escalation testing

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

One-click Android kernel rooting tool exploiting CVE-2026-43499 to install KernelSU, with official, bundled, and custom .so payload sources.

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Windows DLL injection tool that injects a custom DLL into a target process to deliver Meterpreter payloads and escalate privileges for remote access.