
Xiaomi-C200-Firmware-Analysis
From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Set of tools to analyze Windows sandboxes for exposed attack surface.

Determine privileges from cloud credentials via brute-force testing.

PoC for CVE-2026-22015: malicious event injects environment variables into serverless functions, overwriting secrets and enabling privilege…

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Exploit implementation for Android Stagefright vulnerability CVE-2015-3864, enabling remote code execution and privilege escalation on Android 5.1.1…

Exploit scripts for CVE-2025-27581

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

Recover the default privilege set of a LOCAL/NETWORK SERVICE account

Testing POC for use cases