
Mergen
Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Patching ROP-encoded shellcodes into PEs

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

Windows KASLR bypass using prefetch side-channel

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Automated Application Generation for Stack Overflow Types on Wireless Routers

Local privilege escalation through macOS 10.12.1 via CVE-2016-1825 or CVE-2016-7617.

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

scanner/exploiter CVE-2026-24061 & CVE-2026-32746

Python script to detect and exploit CVE-2021-44142 in Samba servers, dumping heap cookie and pointer via single SMB connection for vulnerability…

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

CVE-2025-27591

Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions

CVE-2021-4034 for single commcand

Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.

🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.