
project-rvbbit
Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.

Python-Based Pentesting Framework

Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse

WORK IN PROGRESS. RAT written in C++ using Win32 API

A fully implemented kernel exploit for the PS4 on 5.05FW

Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.

PPID Spoofing

64-bit Windows kernel privilege escalation exploit for CVE-2016-0040 (WMI Receive Notification vulnerability) using GDI bitmap manipulation for token…

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Local privilege escalation exploit for CVE-2015-5287 targeting RHEL 7.0/7.1 via abrt/sosreport, intended for authorized security testing and…

Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Unauthenticated IPC Local Privilege Escalation to SYSTEM via Debauchee Barrier Daemon TCP Port 24801

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Educational proof-of-concept for CVE-2015-2291 local privilege escalation via Intel Ethernet driver IOCTL abuse, demonstrating arbitrary kernel…