
BadSamba
This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Demonstrates arbitrary file write and privilege escalation in Hasleo Backup Suite Free <= 4.9.4 via symbolic links, enabling attackers to overwrite…

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…