
CVE-2026-15409
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

Syncord is a CLI-based file synchronization and storage tool that uses Discord as an encrypted file storage.

Proof-of-concept exploit for CVE-2026-24849, an authenticated path-traversal / arbitrary file read in OpenEMR's Fax/SMS (EtherFax) module. Any…

Remote administration service which uses twitter as a command and control server

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

(extensible) Data Exfiltration Toolkit (DET)

PyExfil — Python 3 toolkit for researching and stress-testing data exfiltration techniques across network, physical, and steganographic channels. For…

Easy files and payloads delivery over DNS

Exploitation Framework for ATtiny85 Based HID Attacks

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Next Generation Firewall Audit and Bypass Tool

File Injector is a script that allows you to store any file in an image using steganography


peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Proof of concept of LibreOffice remote arbitrary file disclosure vulnerability

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

Extraction of iMessage Data via XSS