
CVE-2024-6387
Proof of concept python script for regreSSHion exploit.

Proof of concept python script for regreSSHion exploit.

Palo Alto - CVE-2026-0300 exploit

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods


Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

OpenSTAManager RCE Exploit (CVE-2026-38751)

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

PEDA - Python Exploit Development Assistance for GDB

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

PoCs and tools for investigation of Windows process execution techniques

MCP Server for Metasploit

bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…