
PrivFu
Kernel mode WinDbg extension and PoCs for token privilege investigation.

Kernel mode WinDbg extension and PoCs for token privilege investigation.

Windows protocol library, including SMB and RPC implementations, among others.

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Identify privilege escalation paths within and across different clouds

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

A security auditing toolkit for CVE-2026-31431 vulnerability research

This is just a quick note on how to exploit these vulnerabilities to get root.

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Proof-of-concept exploit for CVE-2023-0386, a Linux OverlayFS local privilege escalation vulnerability. Demonstrates how incorrect file capability…

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…