
LolModapi
Local privilege escalation exploit for MSI Dragon Center's MODAPI.sys driver, abusing unauthenticated MSR writes to bypass SMEP and gain SYSTEM.

Local privilege escalation exploit for MSI Dragon Center's MODAPI.sys driver, abusing unauthenticated MSR writes to bypass SMEP and gain SYSTEM.

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A third-party Gopher Assassin for the Havoc Framework.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Use YARA rules on Time Travel Debugging traces

Execute shellcode files with rundll32

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

PoC for popping a system shell against the LnvMSRIO.sys driver

Safari 1day RCE Exploit

A fully implemented kernel exploit for the PS4 on 5.05FW

Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…