
CdpSvcLPE
Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527

This is working POC of CVE-2022-36271

PoC for LPE with QlikView

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.