
DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

How to spoof the command line when spawning a new process from C#.

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Tips on how to write exploit scripts (faster!)

Hide memory artifacts using ROP and hardware breakpoints.

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

This is a concept poc of command and control server implemented over blockchain

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).