
Relapse-Exploit
PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

Hands-on lab reproducing CVE-2025-22457: sets up Docker attacker/victim containers, finds stack addresses with GDB, and delivers a msfvenom reverse…

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

Analysis and ARM64 reproduction of Copy Fail (CVE-2026-31431)

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Remote DLL Injection with Timer-based Shellcode Execution

Abusing the win32k.sys kernel callback mechanism for arbitrary code execution

SecurityTube Linux Assembly Expert x86 Exam


A collection of my shellcode samples.

forensics-decoding-powershell-payloads

Write up exploit failed chain and experience tryin to sell your first nday

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

This is a custom ASCII AND/SUB Encoder developed during my preparation for the legacy OSCE/CTP course