
exploits
Proof-of-concept exploits for web apps, routers, and local privilege escalation, including RCE, SQL injection, shell uploads, and device takeover…

Proof-of-concept exploits for web apps, routers, and local privilege escalation, including RCE, SQL injection, shell uploads, and device takeover…

Windows local privilege escalation exploit for CVE-2018-8120 supporting x32 and x64 architectures, tested on multiple Windows 7 and 2008 variants.

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Manipulates compiled executables (.exe/DLL) to evade EDRs by removing IoC strings, inflating file size, and cloning code-signing certificates for…

Cross-platform C2 framework using Notion API for stealthy command execution, port scanning, privilege escalation, file download, and shellcode…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Pure PowerShell exploit for CVE-2021-1675 (PrintNightmare) that escalates privileges locally by adding an admin user or loading custom DLL payloads.

Exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo, enabling local privilege escalation. Includes target list and…

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

A standalone python script which utilizes python's built-in modules to enumerate SUID binaries, separate default binaries from custom binaries,…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

A tool to transform Chromium browsers into a C2 Implant