
AMSI-Bypass
Lists of AMSI triggers (VBA, JScript / VBScript)

Lists of AMSI triggers (VBA, JScript / VBScript)

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).


Covert data exfiltration via DNS

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

CVE-2020-16899 - Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule

Zeek package detecting CVE-2022-26937 exploitation attempts against Windows NFS servers via Network Lock Manager protocol analysis.

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Test cases for broken MIME and tools to generate and process these

PoC and vulnerability report for CVE-2025-47827.

Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via SolarWinds Dameware MRC smart card authentication bypass.

This is the exploit of CVE-2019-17240.

CVE-2020-27358 and CVE-2020-27359

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via X-Forwarded-For header manipulation and anti-CSRF token reuse.

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE