
Stuxnet
Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

From deobfuscating code.js to root, CVE-2023-0386

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

Proof of Concept for CVE-2020-0665, a.k.a. SID Filter Bypass.

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Android Remote Access Trojan