
UnjailMe
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

PoC Code for CVE-2018-18714 (exploit by stack overflow)

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Direct Memory Access (DMA) Attack Software

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

find dll base addresses without PEB WALK

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

GhostLock (CVE-2026-43499) for OPPO Find X5 Pro (PFEM10) — OPlus watchdog & heap-spray detector reverse engineering

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)

A fully implemented kernel exploit for the PS4 on 5.05FW

Finding Java/C# gadget chains with CodeQL

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.


A rust library that allows you to host the CLR and execute dotnet binaries.

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…