
Aladdin
Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

GPU-accelerated SHA-256 rainbow table implementation based on CDP (Cyclic Digit-sum Projection) structural analysis. AMD RX 9070 XT, OpenCL + Vulkan.

Hands-on detection research repository documenting how APT techniques appear in logs, with practical detection logic, Splunk queries, and Sigma rules…

Python-based exploit checker for CVE-2021-36260 targeting Hikvision IP cameras via HTTP. Performs remote vulnerability verification with…

Proof-of-concept document generator for CVE-2022-30190 (Follina) that creates malicious docx files and hosts an HTTP server to trigger remote code…

This is a PoC for the CVE-2025-24813 and tested in different environments.

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

HTTP request smuggling vulnerability scanner that detects CL.TE and TE.CL desync attacks using multiple payload types, with configurable verification…

Electron-based Android RAT with server-side control panel and client-side backdoor APK generator for remote device administration and penetration…

An x86-64 code virtualizer for VM based obfuscation

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

Retargetable machine-code decompiler based on LLVM that translates executable binaries (ELF, PE, Mach-O) into C or Python-like high-level code with…

:zap: Web Debugging Proxy based on Chrome DevTools Network panel.

CKB's vm, based on open source RISC-V ISA