
CVE-2023-44487
PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

The poc of CVE-2026-23744

Simple (relatively) things allowing you to dig a bit deeper than usual.

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…


Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Public Repo for Atomic Test Harness

Collection of offensive techniques for attacking Windows environments, with practical methods for exploitation, privilege escalation, and adversarial…

A simple ptrace-less shared library injector for x64 Linux

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…


Detect EDR's exceptions by inspecting processes' loaded modules


Bypassing UAC with SSPI Datagram Contexts

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…


A POC to disable TamperProtection and other Defender / MDE components