
CVE-2020-1066-EXP
Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

The perfect butler for pentesters, bug-bounty hunters and security researchers

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Some Rust program I wrote while learning Malware Development

💻 ARCH : ARM, ARM64, MIPS, PPC, X86

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

libAppleArchive exploit maker, read the writeup here https://snoolie.gay/blog/CVE-2024-27876

Proof-of-concept exploit for the MSMQ QueueJumper RCE, crafting malformed packets to trigger unauthenticated remote code execution via the Message…

do common hacking tasks with a simple menu

weaponized radare2 vulnerability found by @CaptnBanana and blenk92

Exploit helper for CVE-2019-11932 (WhatsApp GIF RCE) that calculates system() function and ROP gadget addresses for different devices to enable…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

Sickle - Payload Development Kit

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…