
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Technical analysis and proof-of-concept for CVE-2026-21858, an authentication bypass and RCE in n8n, demonstrating LFI, session forgery, and full…

Proof-of-concept exploit for CVE-2026-33725, achieving remote code execution and arbitrary file read via H2 JDBC INIT injection in Metabase…

SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

Exploit for MCPJam Inspector <=1.4.2 that triggers remote code execution via crafted HTTP requests, enabling unauthorized installation of MCP servers…

Langflow Remote Code Execution (RCE) Proof-of-Concept

Proof of Concept for CVE-2026-0770 - Langflow Remote Code Execution

Claude Code Remote Code Execution

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua parser, enabling remote code execution on vulnerable Redis servers.

Detects and exploits Apache Tomcat CVE-2025-55752 directory traversal via Rewrite Valve, enabling PUT-based JSP upload and remote code execution.

PoC for Remote Code Execution Vulnerability in Windows Server Update Service by Microsoft CVE-2025-59287 9.8 CRITICAL

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)