
hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Apple MacOS Screen Sharing Arbitrary File read/write -> RCE

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

fsociety Hacking Tools Pack – A Penetration Testing Framework

A Collection of Over 60 Scripts - updated specifically for the BadUSB function on the FlipperZero.

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Temporarily removes the root password using CVE-2026-31431

Filesystem interaction via firebeam virtual machine execution

Kerberos relaying and unconstrained delegation abuse toolkit

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

I have documented all of the AMSI patches that I learned till now

Azure Post Exploitation Framework

Code execution/injection technique using DLL PEB module structure manipulation

CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."

CVE-2024-36842, Creating Persistent Backdoor on Oncord+ android/ios car infotaiment using malicious script!

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.