
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Multi-threaded PoC exploit for unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload. Features case-bypass, shell verification, and…

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

Exploits CVE-2025-27591 local privilege escalation using a symlink on a world-writable log file to inject /etc/ld.so.preload and spawn a root reverse…

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

Go-based proof-of-concept exploit for CVE-2026-48908, enabling unauthenticated remote code execution on Joomla SP Page Builder via malicious ZIP…

Python exploit and Nuclei template for CVE-2026-48907, a critical Joomla JCE editor access control flaw enabling unauthenticated PHP file upload and…

Exploit for CVE-2026-11645, a V8 out-of-bounds read/write in Google Chrome allowing remote code execution via crafted HTML pages.

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

Python exploit for Apache ActiveMQ CVE-2023-46604 unauthenticated remote code execution with Linux reverse shell payload delivery via XML…

Pre-compiled exploit for CVE-2026-31431 (Copy Fail) with multi-architecture binary builds for x86_64, i386, aarch64, armv7, riscv64, ppc64le, and…

Pre-compiled exploit for CVE-2026-43284 (Dirty Frag) with multi-architecture support (x86_64, i386, aarch64, armv7, riscv64, ppc64le, s390x).…

A modern 32/64-bit position independent implant template

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

Educational deconstruction of CVE-2026-31431 privilege escalation exploit, providing readable Python and C implementations with custom shellcode…