
web3-decoder
Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

Proof-of-concept for CVE-2021-28476, a Hyper-V vmswitch.sys arbitrary pointer dereference allowing guest-to-host denial-of-service and potential RCE.

Chrome V8 n-day exploits that I've written.

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

Detaped is a Python disassembler and decompiler for Duktape. The intended use is for source code review and analysis in situations where you only…

Human-friendly Thrift encoder/decoder

The ACCSvc service creates a Named Pipe with a weak Security Descriptor that allows any authenticated user to connect and send messages. When a…

Automated offset calculator for CVE-2026-43499, enabling precise memory offset computation for vulnerability exploitation and binary analysis.


PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

My take on CVE-2021-30858 for ps4 8.xx

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

PoC code for CVE-2018-16711 (exploit by wrmsr)

Proof of concept exploit of Windows Update Orchestrator Service Elevation of Privilege Vulnerability

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…
