
CVE-2021-34527
PowerShell local privilege escalation exploit for PrintNightmare (CVE-2021-34527) targeting Windows Print Spooler. Embeds custom DLL payload to add…

PowerShell local privilege escalation exploit for PrintNightmare (CVE-2021-34527) targeting Windows Print Spooler. Embeds custom DLL payload to add…

PowerShell implementation of PrintNightmare LPE that adds a local administrator or runs a custom DLL payload.

C-based exploit for CVE-2016-5195 (Dirty COW) using a race condition to overwrite a read-only SUID executable with a custom ELF payload that elevates…

ALL In One Custom Login Page <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+)Privilege Escalation

Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied

Honor 80 GT (MagicOS 8.0.0.128, kernel 5.10.168) privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading

Proof-of-concept C# exploit for CVE-2021-1675 (Windows Print Spooler elevation of privilege), accepting custom driver and DLL paths for targeted…

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

C# .NET assembly for post-exploitation reconnaissance on Windows hosts. Performs LDAP queries, DNS resolution, registry/disk enumeration, Windows…

CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)

Kernel Exploit for CVE-2016-6187 (Local Privilege Escalation)

Proof-of-concept exploit code and detailed writeup for two unpatched vulnerabilities in the Code 27 3D Companion Hub: root shell via ADB in recovery…

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

Proof-of-concept exploit for CVE-2018-5353, a privilege escalation and remote code execution vulnerability in Zoho ManageEngine ADSelfService Plus…

Linux kernel local privilege escalation exploit for CVE-2017-16994, leveraging null pointer dereference and mmap_min_addr bypass to achieve root…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.