Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/tijme/kernel-mii
Privilege EscalationExploit FrameworksPenetration TestingRed TeamingPayload Development
GitHubtijme/kernel-mii

kernel-mii

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

View Repository
852353 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share


Cobalt Strike Beacon Object File foundation for kernel exploitation using CVE-2021-21551.
Built by Tijme. Credits to Alex for teaching me! Made possible by Northwave Security

Description

This is a Cobalt Strike (CS) Beacon Object File (BOF) which exploits CVE-2021-21551. It only overwrites the beacon process token with the system process token. But this BOF is mostly just a good foundation for further kernel exploitation via CS.

Usage

Clone this repository first. Then review the code, compile from source and use it in Cobalt Strike.

Compiling

root@kitploit:~
make

Usage

Load the KernelMii.cna script using the Cobalt Strike Script Manager. Then use the command below to execute the exploit.

root@kitploit:~
$ kernel_mii

Alternatively (and for testing purposes), you can directly run the compiled executable. This will spawn a command prompt as SYSTEM.

root@kitploit:~
$ .\KernelMii.x64.exe

Limitations

  • If the vulnerable driver is not installed, you need to be local admin to install it.

Todo

  • Load the vulnerable driver from memory instead of from disk.
  • Delete the vulnerable driver if it was not preinstalled.
  • Make the exploit stable & compatible with multiple Windows versions.

Issues

Issues or new features can be reported via the issue tracker. Please make sure your issue or feature has not yet been reported by anyone else before submitting a new one.

License

Copyright (c) 2022 Tijme Gommers & Northwave Security. All rights reserved. View LICENSE.md for the full license.

Download Tool