
WAREED-DNS-C2
DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

Chisel new generation, written in rust. SSH under WSS with some customization.

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Wrapper to maximize ISH iOS app capabilities without jailbreak

openssh-cve-2024-6387.sh

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Control a system remotely via telegram

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

Provisioning and sharing system for SBCs

Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via SolarWinds Dameware MRC smart card authentication bypass.

Exploiting Parsec for Windows to gain SYSTEM privileges

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

Critical 0 Day in Car Rental Management System Versions 1.0 - 1.3

Technical analysis and documentation of CVE-2024-6387, a critical remote code execution vulnerability in OpenSSH, detailing exploitation vectors and…

Exploit for CVE-2024-38063, a critical RCE in Windows TCP/IP stack via crafted IPv6 packets, enabling arbitrary code execution and system compromise.