
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…


Reuse open handles to dynamically dump LSASS.

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

An aggressor script for Cobalt Strike to query Windows' GetLastError messages

Load your driver like win32k.sys

SubSeven Legacy Official Source Code Repository

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.