
cormem-read-poc
This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

This is the tool to dump the LSASS process on modern Windows 11

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

Poc for CVE-2025-7771 to modify PPL Protection

Shell Simulation over Net-SNMP with extend functionality

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

Tool to make in memory man in the middle

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

Penetration testing utility and antivirus assessment tool.

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Leaked Windows processes handles identification tool

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

An agent to hotpatch the log4j RCE from CVE-2021-44228.