
WinFlesher
Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Using CVE-2021-40449 to manual map kernel mode driver

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Ask a TGS on behalf of another user without password

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

LSTAR - CobaltStrike Translated to EN

CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.

POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…

Tools for get offsets and adding patch for support i386