
exploitation-course
Offensive Software Exploitation Course

Offensive Software Exploitation Course

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

The swiss army knife of LSASS dumping

A modern 32/64-bit position independent implant template

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

collect for learning cases

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW

Grab ssh keys from ssh-agent

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

CVE-2023-34312

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Windows x64 handcrafted token stealing kernel-mode shellcode

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.

Code execution/injection technique using DLL PEB module structure manipulation

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…