


Windows protocol library, including SMB and RPC implementations, among others.

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Red Team AI Benchmark: Evaluating LLMs for authorized offensive-security tasks. Red Team AI Benchmark is a CLI model-evaluation benchmark. It…

Identify privilege escalation paths within and across different clouds

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

A security auditing toolkit for CVE-2026-31431 vulnerability research

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Some scripts to abuse kerberos using Powershell

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

A proof of concept demonstrating how to use the Hinge dating app as a C2.
