
LibTP_Gadget
Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Exploit for CVE-2024-0311

POC code according to trendmicro's research

Header bypass for CVE-2025-55182 (React Server Components RCE).


An A/V evasion armoring experiment for CVE-2012-4681

CVE-2025-55182-POC

Windows x64 kernel mode rootkit process hollowing POC.

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Tools and Techniques for Red Team / Penetration Testing

Tools and PoCs for Windows syscall investigation.

PoCs and tools for investigation of Windows process execution techniques

Project that brings together several pentest tools

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.