
Nidhogg
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Proof-of-concept exploits for web apps, routers, and local privilege escalation, including RCE, SQL injection, shell uploads, and device takeover…

Exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo, enabling local privilege escalation. Includes target list and…

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

A tool to transform Chromium browsers into a C2 Implant

Automated Linux evil maid attack tool that backdoors initrd images to drop a meterpreter shell and exfiltrate full-disk encryption passwords upon…

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

Windows 10 kernel privilege escalation exploit for CVE-2021-1732, targeting x64 1909 systems with a proof-of-concept implementation.

Cobalt Strike BOF for spawning sacrificial processes with Arbitrary Code Guard, BlockDll, and PPID spoofing to inject shellcode and execute payloads…

Activation Context Hijacking Evasion Tool

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

A Bind Shell Using the Fax Service and a DLL Hijack

Windows local privilege escalation exploit for CVE-2018-8120 supporting x32 and x64 architectures, tested on multiple Windows 7 and 2008 variants.