
chromium-exploit-dev
Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Set of tools to analyze Windows sandboxes for exposed attack surface.

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…


Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).

Recover the default privilege set of a LOCAL/NETWORK SERVICE account

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Determine privileges from cloud credentials via brute-force testing.

exp for CVE-2019-0887

Testing POC for use cases

CVE-2025-6018 + CVE-2025-6019 Privilege Escalation Exploit

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot