
r0ak
Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Using CVE-2023-21768 to manual map kernel mode driver

PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

BOF to run PE in Cobalt Strike Beacon without console creation

MikroTik remote jailbreak for v6.x.x

Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

poc for CVE-2025-24252 & CVE-2025-24132

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

WNF Code Execution Library Using C#

Proof-of-concept exploit for arbitrary file write in Sysmon 14.14, abusing Windows service tracing to achieve privilege escalation.

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

Logrotate race condition exploit that enables privilege escalation by writing arbitrary files, such as reverse shell payloads, into system…