
Phantom-Evasion-Loader
x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

Rust Weaponization for Red Team Engagements.

Exploit code for CVE-2023-29360, a Windows elevation of privilege vulnerability, providing proof-of-concept implementation.

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

poc for CVE-2025-24252 & CVE-2025-24132

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

Exploit script for CVE-2021-21300, a Git vulnerability allowing arbitrary code execution. Provides proof-of-concept code for security testing and…

My experiments in weaponizing Nim (https://nim-lang.org/)

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

Detailed proof-of-concept and technical analysis for CVE-2026-2441, a Chrome CSS use-after-free vulnerability enabling sandboxed renderer RCE via…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

IKEv2, ikeext.dll, CVE-2026-33824, double free, heap grooming, ROP, SKF fragmentation, Windows exploit, anti-debug, obfuscation, API hooking,…

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

KERUI K259 5MP Wi-Fi (Tuya Smart Security Camera) contains a code execution vulnerability

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

CVE-2026-19193 Proof of Concept