
NORM-EDR
Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

PoC exploit for CVE-2015-2291

Volatility plugins for memory forensics, including detection of Gargoyle memory scanning evasion techniques.

Potential Integer Overflow Leading To Heap Overflow in AMD KFD.

Private end-to-end sanitizer reproduction package for six GDCM findings

CVE-2026-46215 DRM GEM UAF Exploit for Linux 7.0 - The first working PoC for linux kernel 7 use after free- by Antonius (sw0rdm4n, w1sdom, ev1lut10n)

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

Exploit for CVE-2018-4407-Memory Corruption

Exploit for CVE-2023-5178

Android Blueborne RCE CVE-2017-0781

Poc for CVE-2025-7771 to modify PPL Protection

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

Proof-of-concept exploit for CVE-2024-30085, a heap-based buffer overflow in the Windows CLDLFT driver leading to local privilege escalation on…

Exploit for AMD SEV-SNP firmware vulnerability CVE-2024-21978, enabling decryption of arbitrary guest memory via memory corruption of context pages.

CVE-2025-24201 WebKit Vulnerability Detector (PoC)

Proof-of-concept exploit for CVE-2024-1065, demonstrating page cache exploitation via a use-after-free in the ARM Mali GPU kernel driver to achieve…

Research repository for CVE-2025-38502, a Linux kernel BPF cgroup local storage out-of-bounds access via tail calls enabling local privilege…