
processhacker-mcp
Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

Docker-based CVE-2023-4911 lab for analyzing glibc ld.so buffer overflow and developing a local privilege escalation exploit with GDB debugging.

This is an exploit for CVE-2017-7047, Works on 10.3.2 and below.

My musings with PowerShell

Windows memory hacking library

Executes at the silicon boundary

Elevates a low-privilege Windows process to SYSTEM via a gdb-assisted ROP token-swap chain, demonstrating CVE-2026-62737 in a lab-only QEMU…

Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel…

CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP

Set of tools to analyze Windows sandboxes for exposed attack surface.

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

CVE-2021-3156 POC and Docker and Analysis write up

Detect Linux rootkits which use signals to elevate process privileges.

Python antivirus evasion tool