
mkPIVM
Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell…

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Exploit for CVE-2026-11645, a V8 out-of-bounds read/write in Google Chrome allowing remote code execution via crafted HTML pages.

A bin2bin code virtualizer for x86-64 PE's

CVE-2023-46604-RCE exploit with Linux reverse shell payload

Pre-compiled exploit for CVE-2026-31431 (Copy Fail) with multi-architecture binary builds for x86_64, i386, aarch64, armv7, riscv64, ppc64le, and…

Pre-compiled exploit for CVE-2026-43284 (Dirty Frag) with multi-architecture support (x86_64, i386, aarch64, armv7, riscv64, ppc64le, s390x).…

micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

A PoC project for embedding shellcode to Hint/Name Table

Magento APSB25-94 Unauthenticated File Upload to RCE (CVE-2026-XXXX) - Eval Shell + Probe Scanner

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…