
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Atlassian Jira unauthen template injection

Windows SmartScreen Security Feature Bypass Vulnerability

Image Payload Creating/Injecting tools

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

Proof of concept python script for regreSSHion exploit.

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Mythic C2 agent targeting Linux and Windows hosts written in Rust

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Win32 and Kernel abusing techniques for pentesters

C++ library that retrieves and spoofs Windows syscall arguments using hardware breakpoints and exception handlers to subvert EDR telemetry.

Proof of concept for CVE-2020-7247 for educational purposes.

Git Web Hook Tunnel for C2

Exploit implementation for Android Stagefright vulnerability CVE-2015-3864, enabling remote code execution and privilege escalation on Android 5.1.1…

exp for CVE-2019-0887

An in-memory minimal CPU for agnostic on-the-fly protocols creation

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…