

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Exploit for CVE-2018-20250 (WinRAR ACE path traversal) with automated payload generation and Metasploit reverse shell integration for penetration…

CVE-2024-10914 Shell Exploit

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Pop shells like a master.

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

A tool to generate obfuscated one liners to aid in penetration testing

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

A Ruby framework designed to aid in the penetration testing of WordPress systems.