
ghostlock-s26
GhostLock (CVE-2026-43499) app for the Galaxy S26 series

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…


A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

Proof-of-concept exploit for CVE-2021-3560, a local privilege escalation vulnerability in Polkit (PolicyKit) on Linux systems, enabling unprivileged…

Tools and Techniques for Red Team / Penetration Testing

Identify privilege escalation paths within and across different clouds

Cracking BitLocker encryption based on CVE-2023-21563 vulnerability

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

THREE different reproduction, WORKDIR, EXEC & RUNC.

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation


CVE-2026-0013 Android EoP PoC - Compiled artifacts for security research (Derivative of inforcqb/cve-2026-0013-exploit)

CVE-2023-3269: Linux kernel privilege escalation vulnerability

PoC for Zerologon (CVE-2020-1472) - Exploit

Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…