
CVE-2026-78006-POC
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

This repo covers some code execution and AV Evasion methods for Macros in Office documents

poc for CVE-2025-24252 & CVE-2025-24132

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

CVE-2020-1048 bypass: binary planting PoC

macOS Initial Access Payload Generator

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

Tools for maintaining access to systems and proof-of-concept demonstrations.

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

A tool to transform Chromium browsers into a C2 Implant