
oxasploits
A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Curated collection of V8 sandbox escape, bypass, and violation reports with issue tracker links, articles, papers, slides, and design documents for…

Curated vulnerability research repository with in-depth writeups, proof-of-concept scripts, and IOC listings for real-world CVEs. Covers root cause…

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Curated archive of public proof-of-concept exploits and vulnerability research writeups covering web, binary, and network security, with a focus on…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

Race-condition exploit for Windows Defender vulnerability that escalates privileges to SYSTEM shell. Tested on Windows 10 and 11, with potential…

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)

Proof-of-concept remote code execution exploit for CVE-2020-0796 (SMBGhost) targeting Windows SMBv3 compression vulnerability with kernel shellcode…

GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

Guide to building a virtual iPhone using VPHONE600AP components from Apple's PCC firmware, with firmware patching, bootchain modification, and kernel…

Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

Metaphor - Stagefright with ASLR bypass

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.