
ditto
Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Automated All-in-One OS Command Injection Exploitation Tool

latest version of scanners for IIS short filename (8.3) disclosure vulnerability

Th3Inspector 🕵️ Best Tool For Information Gathering 🔎

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

Binary String Toolkit (BST). Quickly and easily convert binary strings for all your exploit development needs. 😎

A writeup and theoretical Proof-of-Concept for CVE-2019-19194

how to look for Leaked Credentials !

More examples using the Impacket library designed for learning purposes.

Framework providing TCP/IP-like characteristics over GSM SMS with AES+CTR encryption, enabling secure, ordered message streams for device-to-device…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Exploit for CVE-2020-3952 in vCenter 6.7

A short scraper looking for a POC of CVE-2024-49112

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7