Abusing SSRF to deliver an authenticated command injection payload
☆29Sep 1, 2025Updated 9 months ago
Alternatives and similar repositories for Havoc-C2-RCE-2024
Users that are interested in Havoc-C2-RCE-2024 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is a VxLAN PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion☆31Jul 21, 2025Updated 10 months ago
- SANS Workshop: Active Directory Privilege Escalation with Empire!☆37Nov 12, 2025Updated 7 months ago
- WinDbg plugin to trace module transitions from a debugged driver.☆54Dec 22, 2025Updated 5 months ago
- Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.☆20Jul 8, 2022Updated 3 years ago
- 读取微信联系人列表,版本(3.9.12.51)☆13Mar 22, 2025Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script☆16May 13, 2018Updated 8 years ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆123Dec 7, 2025Updated 6 months ago
- Run shellcode via EnumDesktopsA. C++ implementation☆13Jun 27, 2022Updated 3 years ago
- ☆42Jun 5, 2026Updated last week
- NSecSoftBYOVD POC☆61Feb 12, 2026Updated 4 months ago
- Whether you're a seasoned expert or a beginner, Kali GPT helps streamline your workflow, making penetration testing more efficient and ac…☆30Jun 6, 2026Updated last week
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆112Apr 23, 2026Updated last month
- arm64 linux position-independent shellcode framework☆31Dec 12, 2025Updated 6 months ago
- Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)☆18Aug 2, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆29Jun 1, 2026Updated 2 weeks ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆28Sep 18, 2024Updated last year
- CHAOS RAT web panel path RCE PoC☆30Apr 15, 2024Updated 2 years ago
- ShadowDropper is a utility for covertly delivering and executing payloads on a target system.☆27Jul 4, 2025Updated 11 months ago
- ☆20Nov 8, 2020Updated 5 years ago
- Morpheus is an lsass stealer that extracts lsass.exe in RAM and exfiltrates it via forged and crypted NTP packets. For authorized testin…☆169Jun 19, 2025Updated 11 months ago
- Neo4LDAP is a query and visualization tool focused on Active Directory environments. It combines LDAP syntax with graph-based data analys…☆97Feb 3, 2026Updated 4 months ago
- ☆57Nov 18, 2025Updated 6 months ago
- process hollowing variant using NtCreateSection + NtMapViewOfSection + ResumeThread☆31Jan 9, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A collection of various exploits☆30Sep 17, 2024Updated last year
- Python tool to automatically perform SPN-less RBCD attacks.☆130Jan 7, 2026Updated 5 months ago
- Laravel RCE Exploitation Toolkit☆57Nov 8, 2025Updated 7 months ago
- A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes☆25May 15, 2025Updated last year
- ☆18Feb 15, 2020Updated 6 years ago
- CVE-2023-46818 IPSConfig Python exploit☆18Oct 8, 2024Updated last year
- Enumerate the Domain for Readable and Writable Shares☆23Nov 14, 2025Updated 7 months ago
- Exploitation of CVE-2025-29969☆66Feb 20, 2026Updated 3 months ago
- CVE-2025-50168 Exploit PoC — Pwn2Own Berlin 2025 - LPE(Windows 11) winning bug.☆143Nov 3, 2025Updated 7 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- RCE PoC for Empire C2 framework <5.9.3☆28Feb 24, 2024Updated 2 years ago
- A library to compare Cisco IOS, NX-OS, and IOS-XR configurations☆17Jul 25, 2016Updated 9 years ago
- A remote unauthenticated DOS POC exploit that targets the authentication implementation of Havoc.☆36Nov 16, 2023Updated 2 years ago
- ☆16Oct 30, 2022Updated 3 years ago
- ☆36Jul 1, 2025Updated 11 months ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆66Apr 2, 2025Updated last year
- Bypassing Amsi using LdrLoadDll☆48Jan 8, 2025Updated last year