
Windows-Local-Privilege-Escalation-Cookbook
Windows Local Privilege Escalation Cookbook

Windows Local Privilege Escalation Cookbook

Crack any Microsoft Windows users password without any privilege (Guest account included)

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated…

CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发

CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via Cloud Files API + NTFS junction…

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE)…

CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发

Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection…

Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)

CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving…

The Shadow Attack Framework

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

KslDump — Why bring your own knife when Defender already left one in the kitchen?


A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.