
UACME
Defeating Windows User Account Control

Defeating Windows User Account Control

A collection of awesome penetration testing resources, tools and other shiny things

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

An open-source post-exploitation framework for students, researchers and developers.

Penetration tests guide based on OWASP including test cases, resources and examples.

SMBeagle - Fileshare auditing tool.

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows…

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell,…

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…


110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Exploit en Python diseñado para aprovechar la vulnerabilidad de elevación de privilegios CVE-2024-30085

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

A collection of hacking / penetration testing resources to make you better!

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.