
PPLcontrol
Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

The Inspector tool is a privilege escalation helper (PoC), easy to deployed on web server, this tool can list process running with root, check kernel…

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Ask a TGS on behalf of another user without password

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.

This is just a quick note on how to exploit these vulnerabilities to get root.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

CVE-2014-7911 vulnerability and CVE-2014-4322 vulnerability to get root privilege!

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Bypassing NTFS permissions to read any files as unprivileged user.

Using CVE-2021-40449 to manual map kernel mode driver

Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all…

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Proof-of-concept exploit for CVE-2023-37250, a local privilege escalation vulnerability in Windows, with a detailed write-up explaining the roaming…

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…