
forti-research
Proof-of-concept exploiting a Fortinet fortimon3_74.sys kernel driver flaw to bypass PPL and terminate protected processes like lsass.exe via an…

Proof-of-concept exploiting a Fortinet fortimon3_74.sys kernel driver flaw to bypass PPL and terminate protected processes like lsass.exe via an…

PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

LSTAR - CobaltStrike Translated to EN

Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.

Documentation of CVE-2020-36603: a local privilege escalation vulnerability in the Genshin Impact mhyprot2.sys anti-cheat driver allowing…

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Exploitation of echo_driver.sys

PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430,…

PoC for Acronis Arbitrary File Read - CVE-2022-45451

This is my simple implementation of an exploit for the PwnKit vulnerability.

An issue in AVG AVG Anti-Spyware v.7.5 allows an attacker to execute arbitrary code via a crafted script to the guard.exe component