
Zapscape
PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.

Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

CVE-2020-17382 Windows 10 x64 2004 Build 19041.264 Exploit


The Shadow Attack Framework

A script for advanced discovery of Privileged Accounts - includes Shadow Admins

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

Python version of the C# tool for "Shadow Credentials" attacks

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python,…

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Active Directory risk assessment tool that scans for privileged account threats, shadow admins, Skeleton Key malware, SID history abuse, risky SPNs,…

POC experiments with Volume Shadow copy Service (VSS)

Passive AD CS auditor detecting ESC1–ESC16 and Shadow Credentials via read-only LDAP/ACL/registry checks, with prioritized remediation and SIEM-ready…

PowerShell script to detect and remediate the CVE-2021-36934 HiveNightmare privilege escalation vulnerability on Windows 10 by checking SAM hive…