
From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

Microsoft Office / COM Object DLL Planting

A tool for generating fake code signing certificates or signing real ones

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…


Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Code Execution & Persistence in NETWORK SERVICE FAX Service

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

CVE-2023-6401 is a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a malicious `dbghelp.dll` file in the…

Automated DLL Sideloading Tool With EDR Evasion Capabilities

DLL Hijacking in Quickheal Total Security/ Internet Security/ Antivirus Pro (Installers)

DLL Planting in the Corsair iCUE v.5.3.102 CVE-2023-38822

DLL Planting in the CoD MW Warzone 2 - CVE-2023-38821

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

C# PrintNightmare (CVE-2021-1675)