
PasswordFilter
2 ways of Password Filter DLL to record the plaintext password

2 ways of Password Filter DLL to record the plaintext password

CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory



AAD related enumeration in Nim

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Support x86 and x64

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

Execute shellcode files with rundll32

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

Parses Cortex XDR agent database lock files to extract agent settings, uninstall password hash/salt, and security exclusions for red team assessments…

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)