
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

PwnKit-Hunter is here to help you check if your systems are vulnerable to CVE-2021-4043, a.k.a. PwnKit

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

Exploit PoC of CVE-2026-6356


Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Windows Elevation of Privilege Vulnerability CVE-2021-36934

I'll submit the poc after blackhat

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…


CVE-2021-36934 PowerShell Fix


CVE-2021-36934 HiveNightmare vulnerability checker and workaround