
NimGetSyscallStub
Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

Shellcode injection using the Windows Debugging API

Encoded Reverse Shell Generator With Techniques To Bypass AV's

Python script that wraps nasm/objdump to quickly generate shellcode bytes from assembly instructions or compiled ELF binaries, supporting multiple…

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

An efficent Script To Generate FUD Persistent Reverse Shell For Red Teaming. Don't Upload Generated Stub On Virustotal

Linux Shared Library to Shellcode Loader

Python-based proof-of-concept exploit for CVE-2023-2255 (LibreOffice RCE) that generates malicious ODT files to drop a webshell via arbitrary command…

Multi-CVE WebLogic deserialization exploit builder with support for process builder, serialized, and URL-based payloads, enabling remote command…

golang script for bypass AV and work only in windows platform

Generates reverse shell payloads for remote access, facilitating penetration testing and red team operations. Includes a listener setup for external…

Extracts executable shellcode from compiled binary files and outputs escaped hexadecimal byte strings (e.g., \x45\x6e) for exploit development and…

Generate Windows 11 x64 reverse TCP shellcode with PIC technique, supporting C, Python, C#, and PowerShell output formats for red team engagements.

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

PowerShell-based exploit for CVE-2014-4113 targeting x64 Windows systems with remote payload download and execution.

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python exploit for CVE-2026-38751 enabling authenticated remote code execution on OpenSTAManager 2.10 via malicious module upload, with interactive…

Proof-of-concept exploit for CVE-2025-3969 providing OS command injection, web shell, and interactive shell capabilities for penetration testing.