
Follina_MSDT_CVE-2022-30190
Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

BOF combination of KillDefender and Backstab

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

Official guidance and workarounds for CVE-2022-30190, a remote code execution vulnerability in the Microsoft Support Diagnostic Tool (MSDT)…

An NSIS script that helps deploy and roll back the mitigation registry patch for CVE-2022-30190 as recommended by Microsoft

Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

A centralized resource for previously documented WDAC bypass techniques

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

PowerShell scripts to apply and restore Microsoft's registry-based workaround for CVE-2022-30190 (Follina) vulnerability, deployable via InTune for…

A PowerShell script that automates the security assessment of Microsoft 365 environments.

patching N-day of CVE-2026-26114 before microsoft. where microsoft could not patch 100% in many months. but FAC security did it

这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…

This simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and…