


A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.


Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover


Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework


Auto exploitation tool for CVE-2024-24401.

Mass scanner for CVE-2024-24919

