
nocturne
A bin2bin code virtualizer for x86-64 PE's

A bin2bin code virtualizer for x86-64 PE's

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

An Interactive Binary Patching Plugin for IDA Pro

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Search for Unix binaries that can be exploited to bypass system security restrictions.

Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.

A foundational C library for building operationally credible offensive capabilities

Generalized VMProtect devirtualizer supporting versions 1.x–3.x. Standalone CLI tool and Ghidra plugin for automated bytecode decoding, handler…

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

Root-cause analysis of CVE-2026-54107: a use-after-free in Windows win32kfull.sys with race condition debugging, static analysis, MSRC triage…

Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

Proof-of-concept exploit for CVE-2025-63946, a local privilege escalation in Tencent PC Manager via symlink attacks on temporary directories,…

Technical analysis and proof-of-concept for CVE-2024-6387, a race condition in OpenSSH signal handling enabling unauthenticated remote code execution…

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.