
CVE-2024-37726-MSI-Center-Local-Privilege-Escalation
Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU…

PoC and vulnerability report for CVE-2025-47827.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell,…

Dumps LSASS memory by abusing Windows Error Reporting service over ALPC, enabling credential extraction and offline analysis on Windows systems.

Direct Memory Access (DMA) Attack Software

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

Extract Windows credentials directly from VM memory snapshots and virtual disks

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Educational repository of offensive security source code: remote shells, ELF injectors, crypters, memory injection, and droppers for Linux,…

tool to extract passwords from TeamViewer memory using Frida

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Executes arbitrary ELF binaries directly from memory on Linux without touching disk, enabling stealthy red-teaming and anti-forensic operations via a…

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…