
RansomLord
RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

CVE-2017-4878 Samples - http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…

Windows CLFS LPE exploit PoC for security research

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

AV/EDR evasion via direct system calls.

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…

SUIDGuard - a TrustedBSD Kernel Extension that adds mitigations to protect SUID/SGID processes a bit more

Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)

Use cve-2026-36425 killer edr,360 can killer

Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy

Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver…

Kernel-mode Windows driver that blocks CVE-2017-11882 exploitation by intercepting process creation and denying malicious child processes spawned by…

Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit