
CVE-2026-66804
Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Activation Context Hijacking Evasion Tool

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

DLL-injectable internal game cheat for Plutonium BO2 zombies

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Code Execution & Persistence in NETWORK SERVICE FAX Service

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.