
DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

How to spoof the command line when spawning a new process from C#.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Tips on how to write exploit scripts (faster!)

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

Hide memory artifacts using ROP and hardware breakpoints.

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…