
CVE-2025-21479-FX5P
Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)

Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

A rust library that allows you to host the CLR and execute dotnet binaries.

Now You See Me, Now You Don't

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

find dll base addresses without PEB WALK

A fully implemented kernel exploit for the PS4 on 5.05FW

Collects files and commands post-exploitation, formats them into Markdown reports, and helps find sensitive information for red team reporting.

Python script to efficiently find files on UNIX like file systems with specific properties (quicker than find)

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…