
DoubleStar
A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A Rust template for writing Beacon Object Files (BOFs)

PoC for popping a system shell against the LnvMSRIO.sys driver

Passive UAC elevation using dll infection

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

Modern PIC implant for Windows (64 & 32 bit)


Proof-of-concept exploit for CVE-2026-46243, leveraging a fake NSS library and namespace manipulation to escalate privileges via cifs.upcall.

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

Cobalt Strike AggressorScripts CVE-2020-0796

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

all 4.4 ubuntu aws instances are vulnerable

D/Invoke implementation in Nim

A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc

Proof-of-concept exploit for CVE-2016-0051 (MS16-016) achieving local privilege escalation to SYSTEM on Windows 7, with compiled binaries and…

Injects x64 managed DLLs into GUI processes via SetWindowsHook, with a modular C# payload runner and LSASS dump POC for red-team/offensive Windows…

PoCs and technical analysis for three Cisco AnyConnect Windows vulnerabilities: local privilege escalation (CVE-2020-3433), denial of service…

A new simple and powerfull packer for malware