
SharpKiller
Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Unauthenticated remote command execution exploit for SPIP CMS 4.2.8 (CVE-2024-7954) with proxy support and live output retrieval.

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Cobalt Strike BOF for live Windows enumeration of open file handles, revealing which process has locked a target file on disk during…

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

Fish Live In Trees