
Joomla-webshell-plugin
A webshell plugin and interactive shell for pentesting a Joomla website.

A webshell plugin and interactive shell for pentesting a Joomla website.

Adversary emulation and C2 framework for security research

Unified repository for different Metasploit Framework payloads

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

Python PoC exploiting Apache Tomcat CVE-2025-24813 partial PUT deserialization RCE, with auto variant detection, ysoserial gadget chains, and reverse…

Reference resources for Google's vulnerability reward programs, including domain tiers, OSS repository tier lists, and rewarded patch examples for…

Serverless C2 transport plugin for AdaptixC2 v1.2 using AWS Lambda + DynamoDB as the relay infrastructure.

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

XML Signature Wrapping Burp Suite Extensions

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

Proof-of-concept and research material for CVE-2026-4480, an OS command injection RCE in the Samba printing subsystem via the %J print command…

Spicy malware 0day. Full kill-chain malware: exploit, pivot, c2, persistence. Rust converted to pseudo-code - if you're smart you can build it…

EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

A Multi-vector DoS tool for Cybersecurity Red Teamers' .

Redis RCE through Lua Sandbox Escape vulnerability

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's