
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

A loader for bitbucket 2022 rce (cve-2022-36804)

CVE-2026-24061

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai

Working proof of concept for NextJS RCE to establish a reverse shell. [React2Shell]

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Repository to exploit CVE-2023-46604 reported for ActiveMQ

Control a system remotely via telegram

Proof-of-concept exploit for unauthenticated remote code execution in Apache HugeGraph Server via Groovy injection. Supports single and multi-target…