
CVE-2016-5636
CVE-2016-5636

CVE-2016-5636

Notion as a platform for offensive operations

EGESPLOIT is a golang library for malware development

PowerSploit - A PowerShell Post-Exploitation Framework

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

Builds a shell.so reverse shell payload for CVE-2025-1974 (IngressNightmare) using Alpine Linux in Docker, with hardcoded IP and port configuration.


Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.