Skip to content
View mattreduce's full-sized avatar

Organizations

@hashivim @MythicAgents @srcmtd

Block or report mattreduce

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

⚠️ poc

Proof of concept exploits
32 repositories

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Java 1,139 556 Updated Apr 26, 2024

CVE-2022-0185

C 377 57 Updated Apr 25, 2022

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

Python 164 30 Updated Jan 4, 2024

The Dirty Pipe Vulnerability

Go 46 9 Updated Mar 8, 2022

CoreFollowUp phishing attack on macOS

Objective-C 15 Updated Mar 15, 2022

A proof of concept for a clickjacking attack on macOS.

Swift 97 15 Updated Feb 12, 2024

Find CVE PoCs on GitHub

Go 161 25 Updated Aug 1, 2025

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

C 1,663 184 Updated Oct 19, 2023

Ransomware simulator written in Golang

Go 471 55 Updated Jun 30, 2022

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

7,550 1,306 Updated Mar 2, 2026

Abuse the node.js inspector mechanism in order to force any node.js/electron/v8 based process to execute arbitrary javascript code.

Rust 334 26 Updated Sep 9, 2024

An example of how to use chromedp to run Chrome headless with the remote debugger port programmatically (is still a wrapper around the Chrome binary)

Go 4 Updated Oct 17, 2022

A simple bash TCP port scanner

Shell 23 9 Updated Jul 1, 2023
C# 68 13 Updated Oct 17, 2022

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.

C 411 37 Updated Dec 21, 2022

A script to automate privilege escalation with CVE-2023-22809 vulnerability

Shell 161 35 Updated Feb 15, 2023
Objective-C 129 12 Updated Apr 25, 2023

A prototype malware C2 channel using x509 certificates over mTLS

Python 152 15 Updated Mar 15, 2024

Experiments in weaponizing Crystal for offensive operations.

Crystal 29 3 Updated Mar 23, 2023

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX

Python 1,099 164 Updated Jun 10, 2024

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

C++ 761 95 Updated Jan 26, 2025

This program is designed to demonstrate various process injection techniques

C# 1,227 192 Updated Aug 7, 2025

A Windows potato to privesc

C 390 66 Updated Aug 26, 2024

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities

Python 1,692 155 Updated Oct 23, 2024

PoC and Detection for CVE-2024-21626

76 12 Updated Feb 6, 2024

Fragtunnel is a proof-of-concept (PoC) TCP tunnel tool that you can use to tunnel your application's traffic and bypass next-generation firewalls en route to the target.

Python 220 33 Updated Jun 4, 2024

Credentials Dumper for Linux using eBPF

C 1,157 65 Updated Sep 9, 2024