
phishing-frenzy
Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Proof-of-concept exploit for CVE-2019-5420 targeting Rails development mode secret token disclosure to escalate privileges via cookie manipulation.

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Bash-based proof-of-concept exploit for CVE-2016-2098, targeting Ruby on Rails Action Pack remote code execution via unrestricted render method.

Interactive OAuth phishing toolkit for Office365 that performs token theft, email search/sending, file exfiltration, and document replacement via…

Pseudo shell for exploiting CVE-2013-0156, providing a command-line interface for automated exploitation of the Ruby on Rails XML/YAML parser…

Metasploit module for CVE-2015-3224 that enables arbitrary command execution in Ruby on Rails Web Console by extending the original RCE module with…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Proof-of-concept exploit for CVE-2019-5736, a Docker container escape via runc binary overwrite, enabling host shell access through libseccomp…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Proof-of-concept exploit for CVE-2025-15556, demonstrating update integrity bypass in Notepad++ WinGUp updater via MITM proxy or DNS spoofing,…

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

Python script that crafts TNEF-encoded Outlook emails with CVE-2023-23397 exploit payloads and sends them via SMTP, enabling NetNTLM credential theft…

OpenCATS <= 0.9.4 RCE (CVE-2021-41560)