
tools
Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Some setup scripts for security research tools.

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Collection of shellcode and proof-of-concept exploits for known vulnerabilities, intended for local testing and verifying software or network…

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

A collection of my shellcode samples.

Collection of pentesting scripts

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

An Interactive Binary Patching Plugin for IDA Pro

Educational repository of offensive security source code: remote shells, ELF injectors, crypters, memory injection, and droppers for Linux,…

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Hide your Powershell script in plain sight. Bypass all Powershell security features

Proof-of-concept SEH buffer overflow exploit for BlazeDVD 5.0 via crafted .plf playlist file, generating a reverse shell payload with msfvenom for…

Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…