
Detect-It-Easy
Program for determining types of files for Windows, Linux and MacOS.

Program for determining types of files for Windows, Linux and MacOS.

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel race condition enabling unprivileged writes to read-only files and privilege…

Proof-of-concept demonstrating a Windows Cloud Files access-check bypass (CVE-2026-83991) that converts a read-only file into a cloud placeholder via…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring

CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via Cloud Files API + NTFS junction…

Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

Windows utility that uses the vulnerable WiseDelfile64.sys driver affected by CVE-2025-66680 to enable kernel-assisted file deletion.

Exploit PoC for CVE-2026-31431 that uses AF_ALG and splice() to overwrite Linux page cache and patch /usr/bin/su in memory, escalating unprivileged…

CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets

Generates crafted TIFF/DNG files to trigger out-of-bounds writes in Samsung's libimagecodec.quram.so, including binary analysis and reproduction…

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

Copy fake in-memory files to disk using overlayFS

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

The project documents the completion and analysis of the Fragnesia (CVE-2026-46300) TryHackME lab, which demonstrates a Linux kernel page -cache…

Linux kernel local privilege escalation exploit for CVE-2026-31635 that corrupts page cache via RxRPC in-place decryption, overwrites read-only…

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…