
Christmas
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Offensive Windows technique that bypasses EDR solutions by combining IAT hooking, dynamic SSN resolution, and indirect system calls to hide execution…

A toolset to make a system look as if it was the victim of an APT attack

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

Windows local privilege escalation exploit that abuses the PrintNotify COM service to elevate privileges to SYSTEM via a Potato-style attack.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

A payload delivery system which embeds payloads in an executable's icon file!

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

Diagnostic benchmark that measures LLM vulnerability to Affective Contextual Erosion and liminal attack vectors, quantifying attentional collapse…

Abuses SYSTEM/TrustedInstaller privileges to unload WdFilter and disable Defender Tamper Protection, blinding MDE telemetry on affected Windows…

Python PoC demonstrating CVE-2026-22020: exploitable weak seed in quantum key distribution privacy amplification, reducing final key entropy.

PoC simulation of a critical CCSDS telecommand replay vulnerability in satellite command systems, demonstrating missing sequence-number validation…