
CVE-2024-26229-BOF
BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells,…

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…


CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

Tunnel TCP connections through a file

Demo project how to bypass the disable_functions security control of PHP on Linux

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

C exploit collection for Linux Dirty Pipe (CVE-2022-0847) local privilege escalation, including read-only file overwrite and SUID binary hijacking,…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

My experiments in weaponizing Nim (https://nim-lang.org/)

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…