
NfSpy
ID-spoofing NFS client

ID-spoofing NFS client

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Proof-of-concept for arbitrary file delete vulnerability in Cisco Secure Client and AnyConnect, enabling privilege escalation to SYSTEM via Windows…

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Proof-of-Concept for privileged file read through CheckPoint SNX VPN Linux Client

Research framework for CVE-2025-33073, a Windows SMB Client privilege escalation vulnerability. Provides malicious SMB server and client exploit…

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell) RCE

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

POC for the flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows that allows an attacker to execute code at a SYSTEM level via…

Local privilege escalation exploit for Trend Micro OfficeScan Client <=10.0 via misconfigured ACLs on the installation folder, enabling system-level…

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.