
Bropper
An automatic Blind ROP exploitation tool

An automatic Blind ROP exploitation tool

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

CVE-2020-0601 exploit tool that computes alternative ECC private keys from public certificates, enabling certificate spoofing via curve parameter…

Universal stack-based buffer overfow exploitation tool

Exploit for CVE-2024-21980 targeting AMD SEV firmware to decrypt arbitrary memory of decommissioned SEV-SNP guests via a command buffer enforcement…

Exploit for AMD SEV-SNP firmware vulnerability CVE-2024-21978, enabling decryption of arbitrary guest memory via memory corruption of context pages.

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

Exploit for AMD SEV-SNP firmware vulnerability (CVE-2023-31355) that decrypts arbitrary memory of decommissioned guests by corrupting the UMC key…

Python tool exploiting CVE-2018-20250 found by CheckPoint folks

Advanced ransomware using process injection and kernel driver loading via CVE-2019-16098 to encrypt files, disable recovery, and demand ransom. For…

Bypass for Symantec Endpoint Protection's Client User Interface Password

Encrypted PE Loader Generator

Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Patching ROP-encoded shellcodes into PEs

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Local privilege escalation through macOS 10.12.1 via CVE-2016-1825 or CVE-2016-7617.