
CVE-2026-78006-POC
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Tools that trigger False Positive AV alerts

A unique technique to execute binaries from a password protected zip

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

XLL Phishing Tradecraft

yet another AV killer tool using BYOVD

PowerShell Remote Download Cradle Generator & Obfuscator

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…