
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

PoCs and tools for investigation of Windows process execution techniques

COFF and BOF Loader written in Nim

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…


Code Execution & Persistence in NETWORK SERVICE FAX Service

Single-file HTML proof-of-concept for WordPress pre-auth reflected XSS (CVE-2026-64638), demonstrating unauthenticated JavaScript execution and an…

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

PowerSploit - A PowerShell Post-Exploitation Framework

Single stub direct and indirect syscalling with runtime SSN resolving for windows.

A cross platform C2/post-exploitation framework.

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

PoC MSI payload based on ASEC/AhnLab's blog post