
cve-2026-6471-postgres-logical-decoding-dlopen
Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability

More examples using the Impacket library designed for learning purposes.

A rust library that allows you to host the CLR and execute dotnet binaries.

Xenotix Python Keylogger for Windows.

A BOF designed to inspect processes memory and addresses

MAL-002: Force System Restart via Installed Windows MSIs

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

ADManager Plus Build < 7210 Elevation of Privilege Vulnerability

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation,…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Educational write-up and test-mode PoC for CVE-2026-92162, a path traversal in Flatpak's DeployAppstream arch parameter enabling root directory…

Scripted Local Linux Enumeration & Privilege Escalation Checks