
xnuspy
an iOS kernel function hooking framework for checkra1n'able devices

an iOS kernel function hooking framework for checkra1n'able devices

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

The first analysis framework for CPU microcode

Injects code into ELF executables post-build

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Working Python test and PoC for CVE-2018-11776, includes Docker lab

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

A script to exploit CVE-2020-14144 - GiTea authenticated Remote Code Execution using git hooks

exp for CVE-2019-0887

Hook for the PoC for exploiting CVE-2024-32002

CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Here is the CVE-2025-65817

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution