

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

A collection of awesome penetration testing resources, tools and other shiny things

Remote operations commands implemented using Beacon Object Files

This Script will help you to gather information about your victim or friend.

abusing windows toast notifications for fun and user manipulation

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

using the use of CVE-2026-0776 discord "asks" for admin allowing a cmd to be opened as admin

This is a proof-of-work for abusing git's clean filter against IDEs & Sublime.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Tool made to automate tasks of pentesting.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Winrar Exploit CVE-2023-38831

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.