
Potato
Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

A security auditing toolkit for CVE-2026-31431 vulnerability research

Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

C# Tool to interact with MS Exchange based on MS docs

New generation of wmiexec.py

Some scripts to abuse kerberos using Powershell

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Leverage WindowsApp createdump tool to obtain an lsass dump


Exfiltrate data over screen interfaces

Proof-of-concept exploit for CSRF to RCE in Backdrop CMS 1.20 (CVE-2021-45268) using malicious plugin upload.

Demo project how to bypass the disable_functions security control of PHP on Linux

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…


Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…