
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

A basic emulation of an "RPC Backdoor"


🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

Kill AV/EDR leveraging BYOVD attack

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Security research project

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

A fully implemented kernel exploit for the PS4 on 5.05FW

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Linux Eelvation(持续更新)

PPID Spoofing

Windows Elevation(持续更新)

A collection of tools to enumerate and analyse Windows DACLs

A fully implemented kernel exploit for the PS4 on 5.05FW

Demo project how to bypass the disable_functions security control of PHP on Linux