
CVE-2026-43499-S26
Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

A third-party Gopher Assassin for the Havoc Framework.

Use YARA rules on Time Travel Debugging traces

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Dynamic shellcode loader with sophisticated evasion capabilities

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Exploit and firmware analysis toolkit for Canon MF644 printer vulnerabilities, including Python exploits, ARM shellcode, and IDA Pro loader scripts…

This repo stores necessary files for the analysis blog which will come soon

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

CVE-2025-55182漏洞检测工具

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

Self contained htaccess shells and attacks

Extending of metasploit-framework

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

complex webshell manager, quasi-http botnet.

A fully featured Windows backdoor that uses email as a C&C server

Work in Progress. RAT written in C++ using wxWidgets