
One-Lin3r
Gives you one-liners that aids in penetration testing operations, privilege escalation and more

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Freedom Fighting Mode: open source hacking harness

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

A BOF to enumerate system process, their protection levels, and more.

Yet Another PHP Shell - The most complete PHP reverse shell

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

Exploit for CVE-2021-4034 (PwnKit) that provides a root shell via polkit pkexec. Includes a dry-run mode to test vulnerability and a one-liner script…

More portable PoC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux

For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Course enrolments allowed privilege escalation from teacher role into manager role to RCE

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

There are 2 exploitation methods that exploit CVE-2022-27666. For more info on how to use these code bases please check my blog.

More specific : Dirty COW (CVE-2016-5195)