
imMapper
Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.


Walkthrough of CVE-2020-15416 buffer overflow exploit for Netgear R7000 router, including QEMU user-mode debugging environment setup and detailed…

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Summary of Cyber Security interview questions I have been through, hope this helps

A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.

Proof-of-concept exploit for CVE-2023-0386, a Linux OverlayFS local privilege escalation vulnerability. Demonstrates how incorrect file capability…

Technical analysis of CVE-2021-3493, an Ubuntu OverlayFS local privilege escalation vulnerability, including root cause explanation and affected…

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Example payload for CVE-2022-21894

Technical write-up and exploit code for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android that leads to remote code execution via a…

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…