
Remote-BOF-Runner
Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Explotation framework for CVE-2019-11687

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

Android AOSP 10 framework base repository patched for CVE-2021-39696, providing a reference for vulnerability analysis and exploitation of Android…

poc for CVE-2025-24252 & CVE-2025-24132

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)

Android AOSP 10 framework base repository containing the fix for CVE-2023-21097, a vulnerability in the Android framework that could lead to local…

UNIX-like reverse engineering framework and command-line toolset.

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

A POC of a type confusion bug in chakracore framework that leads to code execute.

Root-cause analysis and reachability PoC for CVE-2026-64747, a buffer overflow in the AppleAVE2 kernel extension. Includes reversed IOKit wire…

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Exploit framework targeting CVE-2025-4255, a buffer overflow vulnerability, providing a structured environment for developing and testing exploits.

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

open source port/reimplementation of the Cobalt Strike BOF Loader as is