
PrivFu
Kernel mode WinDbg extension and PoCs for token privilege investigation.

Kernel mode WinDbg extension and PoCs for token privilege investigation.

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

A security auditing toolkit for CVE-2026-31431 vulnerability research

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Some scripts to abuse kerberos using Powershell

New generation of wmiexec.py

This is just a quick note on how to exploit these vulnerabilities to get root.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Leverage WindowsApp createdump tool to obtain an lsass dump

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Windows x64 kernel mode rootkit process hollowing POC.

How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver

C# Tool to interact with MS Exchange based on MS docs

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

How to spoof the command line when spawning a new process from C#.

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.