
CVE-2025-29824-Exploit
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Drltrace is a library calls tracer for Windows and Linux applications.

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…


Endpoint detection & Malware analysis software

Anti-keylogger/anti-rat application for Windows

Source code for SubSeven 2.1.3

Proof-of-concept that abuses Windows Enclave to implement anti-tamper and anti-cheat evasion techniques at the driver level.

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

A python script developed to process Windows memory images based on triage type.

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

Custom CAB template generator for CVE-2021-40444, crafting malicious cabinet archives to exploit Windows MSHTML remote code execution via crafted…

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…