
Striker
Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers

Command and Control server on Slack

Small PHP shell, Controlled by Python Client , connecting over protocol method

Hooked browser communication over MQTT

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781). Executes arbitrary commands on vulnerable…

A simple toolkit to validate, exploit & gain an interactive shell via the react2Shell Next.js RCE.

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

A real exploit for BitBucket RCE CVE-2022-36804

Python-based proof-of-concept exploit for CVE-2021-41773, enabling remote code execution on Apache 2.4.49 servers with custom command and port…

Presents how to exploit CVE-2021-44228 vulnerability.

CVE-2018-1000861 Exploit

A simple python PoC to exploit CVE-2021-26814 and gain RCE on Wazuh Manager (v.4.0.0-4.0.3) through the API service.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

PowerShell to Slack C2

PoC of CVE-2021-26814