
BrokenFlow
A simple PoC to invoke an encrypted shellcode by using an hidden call

A simple PoC to invoke an encrypted shellcode by using an hidden call

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

A lightweight test harness designed to speed up shellcode development by providing an execution environment with integrated crash diagnostics and…

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

Protect process by shellcode

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…

Exploit POC for the bug CVE-2019-8781, found by @LinusHenze

weaponized radare2 vulnerability found by @CaptnBanana and blenk92

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

AV/EDR evasion via direct system calls.


AV/EDR evasion via direct system calls.

A workshop about Malware Development

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Hide your Powershell script in plain sight. Bypass all Powershell security features

A fully featured backdoor that uses Twitter as a C&C server

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications