


Pop shells like a master.

Automated DLL Sideloading Tool With EDR Evasion Capabilities

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Automated ROP chain builder that extracts and analyzes gadgets from binaries using semantic queries, supporting X86/X64 architectures with a Python…

Rust Weaponization for Red Team Engagements.

Windows User-Mode Shellcode Development Framework (WUMSDF)

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Easy-to-understand version of CVE-2026-31431

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

Explicação + Lab no THM

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A foundational C library for building operationally credible offensive capabilities

Header-only C++2x compile-time assembler for x86/x86-64 instruction encoding

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…