
pinky
pinky - The PHP mini RAT (Remote Administration Tool)

pinky - The PHP mini RAT (Remote Administration Tool)

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.


A dynamic unpacking tool

A simple tool to interact with web shells and command injection vulnerabilities

A Windows Remote Administration Tool in Visual Basic with UNC paths

Universal stack-based buffer overfow exploitation tool

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting Windows RDP, with shellcode for x86 systems. Intended for authorized security testing…

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

Python exploit for CVE-2023-3519 targeting Citrix ADC with custom NASM shellcode, PHP backdoor deployment, and SUID privilege escalation.

PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.