
impersonate-proxy
A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

Windows post-exploitation reconnaissance agent that collects system info, privileges, patches, defenses, network config, credentials, and persistence…

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

Proof-of-concept exploit for CVE-2026-42281, an unauthenticated SSRF in MagicMirror² ≤ 2.35.0, enabling config exfiltration, cloud metadata probing,…

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the…

CVE-2022-20818: Local Privilege Escalation via Partial File Read in Cisco SD-WAN

Convert Cobalt Strike profiles to modrewrite scripts