
Cerberus-React2Shell-Scanner-Exploit
Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…


Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

Notion as a platform for offensive operations

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…


Repository containing exploit scripts for various CVEs, targeting web applications, binaries, and network services, suitable for penetration testing…

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting Windows RDP, with shellcode for x86 systems. Intended for authorized security testing…

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.