
WinFlesher
Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

LSTAR - CobaltStrike Translated to EN

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

CVE-2014-7911 vulnerability and CVE-2014-4322 vulnerability to get root privilege!

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Ask a TGS on behalf of another user without password

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Detailed technical analysis and proof-of-concept exploit for CVE-2024-30051, a heap-based buffer overflow in the Windows DWM Core Library enabling…

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Exploit the dirtycow vulnerability to login as root

cve-2025-23266-migration-bypass