
MESH
Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Curated index of game security research: anti-cheat internals, DMA attacks, reverse engineering, kernel/mobile protections, and graphics API hooking…

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

KSU installer for supported firmware with CVE-2026-43499

Android LPE exploit for CVE-2026-43499 targeting OPPO PMG110 (kernel 6.6). Uses futex PI UAF to gain root and install a su daemon via LD_PRELOAD.

Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

Payload injector and HID emulator for Android like Hak5 and rubber ducky

Turns any rooted phone into the legendary USB Rubber Ducky. Android USB HID Keystroke Injector

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers.…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

Exploit for CVE-2022-46395, an Arm Mali kernel driver vulnerability, achieving arbitrary kernel code execution to disable SELinux and gain root on…

Exploit for CVE-2022-20186 in the Arm Mali kernel driver, achieving arbitrary kernel code execution to disable SELinux and gain root on Google Pixel…