
CVE-2025-56383
DLL hijacking to rev shell

DLL hijacking to rev shell

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive



Dumping LSASS with a duplicated handle from custom LSA plugin

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

Memory API proxy via signed mozglue.dll

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

CVE-2018-8440 standalone exploit


New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

A Bind Shell Using the Fax Service and a DLL Hijack

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.