

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Toy scripts for playing with WinDbg JS API

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

Integer overflow in FreeType software, which also affects Chrome

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.



Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

Golang bindings for PE-sieve

My journey through WebKit CVE-2016-4622 Exploitation process

Adaptation of Cassowary CVE-2024-23222 for Linux x86_64