
NimSyscallPacker
Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Linux kernel privilege escalation exploits targeting Netfilter's nf_table module, developed by Team Orca for multiple CVEs.

Exploit script for CVE-2025-6019, a local privilege escalation vulnerability in XFS filesystem, providing automated exploitation with multiple modes…

Exploit for CVE-2021-3156 (Sudo Baron Samedit) targeting Linux x64 with multiple variants for different glibc and sudo versions.

Real world and CTFs exploiting web/binary POCs.

C exploit for CVE-2026-31431, targeting multiple Ubuntu and Kali versions with x86_64 and ARM64 builds.

Oracle VM VirtualBox 7.0.10 r158379 Escape

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel vulnerability affecting multiple distributions, with tested versions and a technical…

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel vulnerability affecting multiple distributions, with a technical writeup and tested…

Linux kernel local privilege escalation exploit for CVE-2026-31431, providing a reliable single-shot PoC with multiple language implementations,…

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

Proof-of-concept exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo enabling local privilege escalation to root.…

Proof-of-concept exploit for CVE-2016-7255 (MS16-135), a Win32k elevation of privilege vulnerability in multiple Windows versions, enabling local…

Local privilege escalation exploit for macOS (CVE-2016-1757) using Mach IPC race condition to bypass SIP and SUID protections, targeting multiple OS…

ARM32 Linux kernel privilege escalation exploit for CVE-2026-43499 (GhostLock futex UAF) targeting Huawei Watch 4 Pro with multiple exploitation…