
process_overwriting
PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

poc for CVE-2025-24252 & CVE-2025-24132

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

Educational exploit implementation for CVE-2007-2447 Samba 3.0.20-3.0.25rc username map script command execution vulnerability with Python SMB client…

My experiments in weaponizing Nim (https://nim-lang.org/)

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Historical archive of exploit code and tools from TESO, including remote exploits, DDoS agents, and development utilities for educational security…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

exploit for CVE-2026-42945

An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products

Evince/xreader/Atril RCE exploit to CVE-2026-46529

PoC code for CVE-2018-15499 (exploit race condition for BSoD)

Local PoC exploit for CVE-2021-43267 (Linux TIPC)