
Xiaomi-C200-Firmware-Analysis
From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Demo project how to bypass the disable_functions security control of PHP on Linux

Windows protocol library, including SMB and RPC implementations, among others.

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

A curated list of awesome OSCP resources

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

How to spoof the command line when spawning a new process from C#.

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Kernel mode WinDbg extension and PoCs for token privilege investigation.