

Don't be evil.

Breathe fresh life into your bricked Nest, now with 100% less evil!

Proof of Concept for CVE-2021-1585: Cisco ASA Device Manager RCE

Proof-of-concept exploit for CVE-2025-1562, a WordPress plugin activation vulnerability allowing remote code execution via crafted REST API requests.

Explore CVE-2022-41741 with the Evil MP4 repository. It offers educational PoCs,and documentation on securing nginx against MP4 file vulnerabilities.…

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

CVE-2023-38831 winrar exploit generator

Python exploit for Moodle Evil Teacher vulnerability (CVE-2018-1133) enabling authenticated remote command execution with proxy support.

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…

The Demo for CVE-2017-11427

Rewrite of the popular wireless network auditor, "wifite"

WiFi Penetration Testing & Auditing Tool

A deauth attack that disconnects all devices from the target wifi network (2.4Ghz & 5Ghz), WPA3 also supported (PMF not tested)

Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research.

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Automated Brute-Force Login Attacks Against EAP Networks.