
smbtakeover
BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

COFF file (BOF) for managing Kerberos tickets.

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…



Create and enumerate hidden desktops.

Indirect syscalls + DInvoke made simple.

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

Linux Shared Library to Shellcode Loader

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.


Python-Based Pentesting Framework

POCs to demonstrate CVE-2026-42167 in ProFTPD


VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

method 59 from UACME in a standalone .C