
xsser
From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

基于Java实现的Shellcode加载器

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

PoC Thread Execution Hijacking for Win32 Code Injection

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

it works on xp (all version sp2 sp3)


CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002

ImaegMagick Code Execution (CVE-2016-3714)

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)