
Ropper
Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

Proof-of-concept exploit for CVE-2023-21752, an arbitrary file delete vulnerability in Windows Backup service, with two variants including privilege…

Use CVE-2020-0668 to perform an arbitrary privileged file move operation.

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Proof-of-concept exploit for arbitrary file write in Sysmon 14.14, abusing Windows service tracing to achieve privilege escalation.

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

Annual small file competition repository with binary golf challenges across themes like polyglots, crashes, self-replication, and downloads,…

Windows Common Log File System Driver POC

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Windows Network File System Crash PoC

Exploit for CVE-2016-2434, a buffer overflow in Android mediaserver enabling arbitrary code execution via crafted media file.