
wptsextensions.dll
WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Code Execution & Persistence in NETWORK SERVICE FAX Service

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

AAD related enumeration in Nim

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Signtool for expired certificates

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Lateral Movement Using DCOM and DLL Hijacking

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

For when DLLMain is the only way

Execute shellcode files with rundll32