


Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

Proof of concept python script for regreSSHion exploit.

Script to exploit CVE-2023-38035

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

MSFvenom Payload Creator (MSFPC)

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

A variation of ProcessOverwriting to execute shellcode on an executable's section

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…