
Remote-BOF-Runner
Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Proof of concept for CVE-2022-31814

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

Powershell implemetation of CVE-2020-7352

Extending of metasploit-framework

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

My experiments in weaponizing Nim (https://nim-lang.org/)

Payload Generation Framework

SharpSploit is a .NET post-exploitation library written in C#

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

MSFvenom Payload Creator (MSFPC)

EXOCET - AV-evading, undetectable, payload delivery tool

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

poc for CVE-2025-24252 & CVE-2025-24132