

A fake host that can be "managed" by Dell OMSA, getting you past the login screen.

POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit



Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)


Tunnel TCP connections through a file

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

UDRL for CS

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Windows x64 kernel mode rootkit process hollowing POC.

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…