
nimvoke
Indirect syscalls + DInvoke made simple.

Indirect syscalls + DInvoke made simple.

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer

WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

Proof-of-concept exploit for CVE-2018-17463 demonstrating arbitrary code execution in Chrome via V8 side-effect annotation bug, using WebAssembly RWX…

Bypassing Linux Executable Space Protection using 20+ years old tools (CVE-2022-25265).

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

OpenSTAManager-RCE-Exploit-CVE-2026-38751

Research artifacts, PoC scripts, and lab assets for the Copy Fail Linux local privilege escalation writeup on https://4xura.com/binex/kernel/copy-fail

Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers.…

Original standalone Proof-of-Concept exploit and execution harness for CVE-2023-20052 (ClamAV DMG XML Entity Expansion).

ChakraCore exploitation techniques

Protect process by shellcode

Proof-of-concept exploit for CVE-2024-6387 targeting vulnerable OpenSSH servers via heap manipulation and race condition to achieve remote code…

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe) enabling local privilege escalation on Linux kernels 5.8–5.16 via pipe buffer manipulation…