
CVE-2002-1120
Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

A fully featured Windows backdoor that uses Gmail as a C&C server

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

spring4shell | CVE-2022-22965

A proof-of-concept exploit for CVE-2025-32433, a critical vulnerability in Erlang's SSH library that allows pre-authenticated code execution via…

A fully featured backdoor that uses Twitter as a C&C server

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

A stealthy Python based Windows backdoor that uses Github as a command and control server

A fully featured Windows backdoor that uses email as a C&C server


A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

Python exploit for CVE-2025-24893 that executes a reverse shell on vulnerable web applications, with shell upgrade instructions.

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.