
CVE-2014-4113
PowerShell-based exploit for CVE-2014-4113 targeting x64 Windows systems with remote payload download and execution.

PowerShell-based exploit for CVE-2014-4113 targeting x64 Windows systems with remote payload download and execution.

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via SolarWinds Dameware MRC smart card authentication bypass.

CVE-2025-3969: Exploit PoC (OS CMD injection, Web Shell, Interactive Shell)

C-based PoC to bypass Windows PayloadRestrictions.dll and wdeg ROP mitigation, enabling payload execution and binary exploitation for security…

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Bash exploit script for CVE-2020-7384, a remote code execution vulnerability in Apache NiFi, with improved usability and quality-of-life enhancements.

Custom CAB template generator for CVE-2021-40444, crafting malicious cabinet archives to exploit Windows MSHTML remote code execution via crafted…

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Adversary Emulation Framework

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Shellcode Compiler

Python AV Evasion Tools