
lsawhisper-bof
A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

CVE-2026-32941 PoC - Sliver Remote OOM

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Generate Payloads and Control Remote Machines. [Discontinued]

Evince/xreader/Atril RCE exploit to CVE-2026-46529

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

PoC code for the LPE and RCE (CVE-2024-31903) attacks against the IBM Sterling B2B Integrator

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

poc for CVE-2025-24252 & CVE-2025-24132

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
