
EternalBlueC
EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Royal Elementor Addons - Unauthenticated Remote Code Execution

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".


Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe) enabling local privilege escalation on Linux kernels 5.8–5.16 via pipe buffer manipulation…

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Hardware Sandbox Toolkit

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

This repo stores necessary files for the analysis blog which will come soon

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!