
LogMeInPoCHandleDup
Exploit for a LogMeIn/GoTo Windows kernel driver race condition that duplicates SYSTEM handles, enabling thread-token impersonation and local…

Exploit for a LogMeIn/GoTo Windows kernel driver race condition that duplicates SYSTEM handles, enabling thread-token impersonation and local…

Proof-of-concept web app built on top of Frida

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

Linux libfprint driver for the Focal-systems FT9201 (2808:93a9) USB fingerprint reader — runs FocalTech's own Windows matching engine natively on…

Imphash-like calculation on Golang binaries

Windows x86 PoC: Stack‑based buffer overflow with custom shellcode on legacy 32-bit Windows.

CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29

Reverse engineering of the engine powering the PriPara games on arcade.

Demonstrate some functionalities of Morion by generating an exploit for CVE-2022-27646 (stack buffer overflow on Netgear R6700v3 routers).

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Deep-dive analysis of Windows CLFS type confusion (CVE-2022-24481) with root-cause explanation, exploitation flow, kernel gadget details, and working…

CVE-2025-65320 proof-of-concept demonstrating cleartext license key extraction from process memory via debugger attachment, enabling software…

frida-stalker based system call tracer on windows(x64).

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes

Stack-based buffer overflow in R 3.4.4. Full exploitation on x86, but only RIP control with gadget analysis on x64 due to program constraints. The…

My take on CVE-2021-30858 for ps4 8.xx

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.