
BackupOperatorToolkit
Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

How to spoof the command line when spawning a new process from C#.

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

Bypass age verification service from redhat

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

[L]ocal [A]uto [R]oot [E]xploiter is a simple bash script that helps you deploy local root exploits from your attacking machine when your victim…

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

Activation cache poisoning to elevate from medium to high integrity (CVE-2024-6769)

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

Determine privileges from cloud credentials via brute-force testing.

Course enrolments allowed privilege escalation from teacher role into manager role to RCE

From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN

CVE-2020-8950 AMD User Experience Program Launcher from Radeon Software Privilege Escalation ( FileWrite eop)

Local privilege escalation exploit for macOS XNU kernel (CVE-2026-43724) that uses an out-of-bounds write in dyld shared-cache slide walk to gain a…