
lsawhisper-bof
A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Penetration testing utility and antivirus assessment tool.

Serving payloads only to allowed processes using Windows projected file system feature

find dll base addresses without PEB WALK

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

The swiss army knife of LSASS dumping

Elevates a low-privilege Windows process to SYSTEM via a gdb-assisted ROP token-swap chain, demonstrating CVE-2026-62737 in a lab-only QEMU…

some gadgets about windows process and ready to use :)

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

Local privilege escalation exploit for CVE-2023-36802 targeting Windows kernel streaming service (MSKSSRV) on Windows 11 22H2, using I/O Ring…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Windows x64 handcrafted token stealing kernel-mode shellcode

Windows process injection methods

A memory-based evasion technique which makes shellcode invisible from process start to end.