
acheron
indirect syscalls for AV/EDR evasion in Go assembly

indirect syscalls for AV/EDR evasion in Go assembly

pinky - The PHP mini RAT (Remote Administration Tool)

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

WORK IN PROGRESS. RAT written in C++ using Win32 API

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Evince/xreader/Atril RCE exploit to CVE-2026-46529

Work in Progress. RAT written in C++ using wxWidgets


CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

CVE-2014-6287

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

Remote code execution exploit for CVE-2022-26809 targeting Windows RPC heap buffer overflow with msfvenom shellcode integration and meterpreter…

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

Meterpreter auto exploit program

DKMC - Dont kill my cat - Malicious payload evasion tool

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

complex webshell manager, quasi-http botnet.