
iMonitorSDK
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…

Local privilege escalation exploit for Windows CVE-2020-17103 in cldflt.sys, abusing a race condition in Cloud Files placeholder handling to elevate…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

CVE-2025-62215 exploit development using Claude Code Agent Team

Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection,…

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…

Technical analysis and proof-of-concept exploit for a symlink vulnerability in Apple's ManagedConfiguration framework, enabling unauthorized file…

CVE-2018-4331: Exploit for a race condition in the GSSCred system service on iOS 11.2.

Insecure access control in ThreatFire System Monitor's TfSysMon.sys driver allows unprivileged process termination with kernel privileges, enabling…

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

Script to check if system are vulnable to cve-2026-23111

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

Race-condition exploit for Windows Defender vulnerability that escalates privileges to SYSTEM shell. Tested on Windows 10 and 11, with potential…

UEFI bootkit for Windows with Secure Boot bypass, kernel-level persistence, and encrypted HTTPS C2. Features HVCI/UAC bypass, API hooking, and…