
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…


"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

PowerSploit - A PowerShell Post-Exploitation Framework

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

Another Windows Local Privilege Escalation from Service Account to System

Local privilege escalation from SeImpersonatePrivilege using EfsRpc.

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Abuse Impersonate Privilege from Service to SYSTEM like other potatoes do


Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege


Leak of any user's NetNTLM hash. Fixed in KB5040434