
nightHawkResponse
Incident Response Forensic Framework

Incident Response Forensic Framework

DLL Injection tool to unlock guest VMs

CVE-2026-50416: Windows 11 KASLR bypass


Windows Font Driver Type 1 VToHOrigin stack corruption

CVE-2019-2525 / CVE-2019-2548

Private end-to-end sanitizer reproduction package for six GDCM findings

Poc for CVE-2025-7771 to modify PPL Protection

Proof-of-concept script that analyzes Windows memory dumps to recover visited Tor onion services, bypassing Tor Browser's anonymity by exploiting…

Webkit (Safari) - Exploit

Remotely Exploiting The Kernel Via IPv6

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite.…

Windows kernel exploit for CVE-2020-17057 using palette objects with dangling data pointers, targeting type isolation bypass for privilege escalation.

CVE-2026-3805: Use-After-Free in curl SMB connection reuse - heap info disclosure

CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6

SIDECHANNEL+CVE-2022-38029

Simple Process Dumper using DMA over a PCIe FPGA device