
EvilnoVNC
Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Remote operations commands implemented using Beacon Object Files

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…


Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

POC Files for CVE-2019-17497

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

A Phishing Dropper designed to Pentest.

Lnk crafting and research tools

CVE-2025-33053 Proof Of Concept (PoC)

【Teedy 1.11】Account Takeover via XSS

Information Protection & OSINT resources | 一个关于数字隐私搜集、保护、清理集一体的方案,外加开源信息收集(OSINT)对抗

Automated man-in-the-middle attack tool.