


Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

How to spoof the command line when spawning a new process from C#.

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Remove API hooks from a Beacon process.

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

Get your data from the resource section manually, with no need for windows apis

GitBackdorizer (bad name, I know!) Is a proof of concept from Ulisses Castro's talk - 50 ton of backdoors…

All about CVE-2018-14667; From what it is to how to successfully exploit it.

CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

Local privilege escalation exploit for macOS XNU kernel (CVE-2026-43724) that uses an out-of-bounds write in dyld shared-cache slide walk to gain a…

CVE-2023-50254: PoC Exploit for Deepin-reader RCE that affects unpatched Deepin Linux Desktops. Deepin Linux's default document reader…