
ICALL-GADGET
Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

Interactive GDB walkthrough of the House of Apple 2 FSOP technique on glibc 2.43, with a reproducible sandbox covering vtable bypass, stack pivoting,…

Local privilege escalation exploit for MSI Dragon Center's MODAPI.sys driver, abusing unauthenticated MSR writes to bypass SMEP and gain SYSTEM.

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

A shellcode function to encrypt a running process image when sleeping.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Nim Library for Offensive Security Development

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level


Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Execute shellcode files with rundll32

Indirect syscalls + DInvoke made simple.

Dynamically invoke arbitrary unmanaged code