
CVE-2020-1472
Exploit for CVE-2020-1472 (ZeroLogon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

Exploit for CVE-2020-1472 (ZeroLogon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

Proof-of-concept exploit for CVE-2021-4034 (PwnKit) that escalates privileges to root via a shared library injection in polkit's pkexec.

Proof-of-concept exploit for CVE-2024-55503, a local command injection in Termius for macOS via DYLD_INSERT_LIBRARIES, demonstrating arbitrary code…

Proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. Compiles and runs a C payload to…

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

Proof-of-concept for Cisco AnyConnect HostScan local privilege escalation via DLL hijacking and IPC command injection, demonstrating DLL proxying to…

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…


Multiple untrusted search path vulnerabilities in MicroStation 7.1 allow local users to gain privileges via a Trojan horse (1) mptools.dll, (2)…

Tools for get offsets and adding patch for support i386

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

Beacon Object File Loader

Linux kernel privilege escalation exploit for CVE-2026-46331, abusing the traffic control pedit subsystem to corrupt the page cache and execute SUID…

(Demo) 3rd party agent for Havoc

Notion as a platform for offensive operations