
halo-cve-2026-67919
halo cms plugin 1-request rce from a url, PoC + exploit chain

halo cms plugin 1-request rce from a url, PoC + exploit chain

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…


Reuse open handles to dynamically dump LSASS.

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

An aggressor script for Cobalt Strike to query Windows' GetLastError messages

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Load your driver like win32k.sys

PowerSploit - A PowerShell Post-Exploitation Framework

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely