
c-copy-fail
C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Apply a divide and conquer approach to bypass EDRs

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…


WORK IN PROGRESS. RAT written in C++ using Win32 API

Work in Progress. RAT written in C++ using wxWidgets

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

Manual exploit for Firefox RCE CVE-2016-9079 with customizable shellcode, served via HTTP for remote code execution on vulnerable Windows systems.

CVE-2015-7547 initial research.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

Serv-U-FTP CVE-2021-35211 exploit

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying