
gopher47
A third-party Gopher Assassin for the Havoc Framework.

A third-party Gopher Assassin for the Havoc Framework.

indirect syscalls for AV/EDR evasion in Go assembly

Hershell is a simple TCP reverse shell written in Go.

Go shellcode loader that combines multiple evasion techniques

Go package that aids in binary analysis and exploitation

Proof-of-concept exploit for CVE-2018-6574 demonstrating arbitrary command execution via malicious Go plugin injection using CGO shared libraries.

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…

CVE-2018-10933 very simple POC

Golang reverse/bind shell generator

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

Go-based exploit for CVE-2025-32433

Some setup scripts for security research tools.

Adversary Emulation Framework

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.