
CVE-2022-22077
BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

My experiments in weaponizing Nim (https://nim-lang.org/)

Rust Weaponization for Red Team Engagements.

Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)

Adaptive DLL hijacking / dynamic export forwarding

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

a signal handler race condition in OpenSSH's server (sshd)

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

poc for CVE-2025-24252 & CVE-2025-24132