
MMSkillRisk
Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

Simple (relatively) things allowing you to dig a bit deeper than usual.

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Windows And Ways To Break It

Stop Windows Defender programmatically

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

A windows token impersonation tool

PoC-Malware-TTPs

Command-line utility for Windows that enables SeTakeOwnershipPrivilege and modifies file ownership to the current user, granting access to otherwise…

Attempt at Obfuscated version of SharpCollection

Kill AV/EDR leveraging BYOVD attack

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Bypassing UAC with SSPI Datagram Contexts

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…