
CVE-2026-34621
Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Rust Weaponization for Red Team Engagements.

Practice Go programming and implement CobaltStrike's Beacon in Go

PoC Implementation of a fully dynamic call stack spoofer

a reverse TCP tunnel let you access target behind NAT or firewall

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

Lifetime AMSI bypass

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Automatically spawn a reverse shell fully interactive for Linux or Windows victim