
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python exploit for CVE-2026-38751 enabling authenticated remote code execution on OpenSTAManager 2.10 via malicious module upload, with interactive…

Simple CLI tool for the generation of bind and reverse shells in multiple languages

A modern 32/64-bit position independent implant template

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Web-based reverse shell generator supporting multiple payload formats, encoding, listener integration, and raw download mode for penetration testing…

micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.

Generate Windows 11 x64 reverse TCP shellcode with PIC technique, supporting C, Python, C#, and PowerShell output formats for red team engagements.

Linux Shared Library to Shellcode Loader

Shellcode injection using the Windows Debugging API

Modular kernel exploitation framework for CVE-2018-19323 (GIGABYTE GDrv) achieving privilege escalation to SYSTEM with multi-architecture support,…

Reverse shell generator written in Python 3.

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Proof-of-concept exploit for CVE-2025-3969 providing OS command injection, web shell, and interactive shell capabilities for penetration testing.

Converts PE files (EXE/DLL) into position-independent shellcode with optional LZNT1 compression and obfuscation, supporting x86/x64, .NET, and Go…

Threadless Process Injection using remote function hooking.