
Principal-HackTheBox
Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

Password Manager Pro Exploit

public disclosure

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

Impersonate Logged In Accounts & Execute Commands

PwnKit-Hunter is here to help you check if your systems are vulnerable to CVE-2021-4043, a.k.a. PwnKit

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

Exploit PoC of CVE-2026-6356

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

CVE-2022-38532 - Local Privilege Escalation vulnerability in MSI Center Application

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Windows Elevation of Privilege Vulnerability CVE-2021-36934

I'll submit the poc after blackhat

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…