
windows-x86-shellcode-poc
Windows x86 PoC: Stack‑based buffer overflow with custom shellcode on legacy 32-bit Windows.

Windows x86 PoC: Stack‑based buffer overflow with custom shellcode on legacy 32-bit Windows.

Modified .NET deserialization payload for CVE-2021-42321, based on ysoserial.net, that writes files and bypasses Windows Defender to target Microsoft…

Python exploit for CVE-2023-26360 targeting Adobe ColdFusion unauthenticated RCE via log poisoning and template execution, supporting Windows and…

Proof-of-concept exploit for CVE-2021-34427 targeting Birt Viewer 4.8.0 on Windows. Demonstrates exploitation of a remote code execution…

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

Cobalt Strike aggressor script implementing CVE-2020-0796 local privilege escalation via reflective DLL injection for Windows 10 and Server 1903/1909.

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Python exploit for SLmail 5.5 buffer overflow (CVE-2003-0264) that spawns a reverse shell using pwntools and Metasploit's windows/reverse_tcp payload.

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

C++ self-Injecting dropper based on various EDR evasion techniques.

Using CVE-2023-21768 to manual map kernel mode driver

A Bind Shell Using the Fax Service and a DLL Hijack