
PurplePanda
Identify privilege escalation paths within and across different clouds

Identify privilege escalation paths within and across different clouds

generate CobaltStrike's cross-platform payload

Hide your Powershell script in plain sight. Bypass all Powershell security features

C# tool to dump all cookies from Chrome/Edge browsers, including httpOnly and secure flags, for session hijacking and post-exploitation credential…

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

Execute PowerShell code at the antimalware-light protection level.

BOF to run PE in Cobalt Strike Beacon without console creation

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

PowerShell to Slack C2

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

Proof-of-concept exploit for CVE-2026-41089, a Netlogon remote code execution vulnerability in Windows Active Directory environments, for security…

Memory API proxy via signed mozglue.dll

Exploit for Apache Tomcat EncryptInterceptor bypass leading to unauthenticated RCE via Java deserialization on port 4000. Includes lab setup,…

WordPress Backup Guard Authenticated Remote Code Execution Exploit

A list of custom Metasploit modules you can use for penetration testing.

This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…