
moonwalk
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

VMware Aria Operations for Logs CVE-2023-34051

Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Some Rust program I wrote while learning Malware Development

A Bash-based privilege escalation exploit targeting the `below` system performance monitoring tool. This refurbished exploit leverages a symlink…

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)