
Variatype.htb-CVE-2025-66034
Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

Simple & Powerful PowerShell Script Obfuscator

venom - C2 shellcode generator/compiler/handler

C# Reflective loader for unmanaged binaries.

Adversary Emulation Framework

c++ fully undetected shellcode launcher ;)

基于Java实现的Shellcode加载器

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

MSFvenom Payload Creator (MSFPC)

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Use YARA rules on Time Travel Debugging traces

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux