
Tools for maintaining access, exploring, and expanding control within compromised systems and networks.


🛠️ Explore custom C2 TTPs with Aether-C2-Framework, focusing on lightweight Rust implants and stealthy transport stacks to reduce forensic…

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.

Unverified Linux kernel privilege-escalation PoC using msg_msgseg cross-cache reuse to overlap skb and pipe_buffer, altering pipe flags to read…

Python implementation of OpenPsPipeJack

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

CVE-2026-68398 Ubuntu PPPoL2TP use-after-free local privilege escalation

Probes CVE-2026-0075 Android ContactsProvider side channel with a no-permission PoC, enabling root-cause analysis and patched-vs-vulnerable…

CVE-2026-23111 nf_tables catchall UAF — unprivileged LPE for Linux 5.10-6.18. Auto-adaptive exploit with KASLR bypass, arbitrary kernel read, and ROP…

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

vivo/iQOO 临时 root 工具箱 (免解锁临时root, CVE-2026-43499) - 源码与脚本