
efiSeek
Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

GhostLock One-Tap Execution App (CVE-2026-43499)

In-depth technical analysis of Linux kernel CVE-2026-31431 (Copy Fail), a local privilege escalation via AF_ALG in-place scatterlist bug, including…

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

PoC and analysis of a local stack-buffer-overflow in dataSIMS Avionics ARINC 664-1 v4.5.3, with payload breakdown, reproduction script, and CVE…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

machofile is a module to parse Mach-O binary files

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

An IDAPython module for enhancing c++ support on top of ida_kernelcache

nanoMIPS module for Ghidra

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

This module fixes an issue in the kernels filesystem layer (CVE-2021-33909) by kprobe-replacing vulnerable functions during runtime

Android frameworks_av module with modifications addressing CVE-2020-0245, a vulnerability in media framework. Provides patched source code for AOSP…

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…