
ruler
A tool to abuse Exchange services

A tool to abuse Exchange services

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

ChakraCore exploitation techniques

Reverse shell for CVE-2024-28397.

Golang reverse/bind shell generator

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…

Python exploit for CVE-2007-2447 that triggers Samba username map script command injection to open a reverse shell on vulnerable targets.

EXOCET - AV-evading, undetectable, payload delivery tool

Automated exploit tool for CVE-2024-23743 targeting Notion macOS via RunAsNode and enableNodeClilnspectArguments, enabling remote code execution and…

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

Easy-to-understand version of CVE-2026-31431

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

SharpSploit is a .NET post-exploitation library written in C#

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

Script to exploit CVE-2023-38035

Nim Library for Offensive Security Development