
Kernel_VADInjector
Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)

A third-party Gopher Assassin for the Havoc Framework.

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

A Windows Remote Administration Tool in Visual Basic with UNC paths

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Rust-based User-Defined Reflective Loader for Cobalt Strike payloads. Avoids RWX memory pages for OPSEC safety. Includes an extractor tool for loader…

WORK IN PROGRESS. RAT written in C++ using Win32 API

Copy Fail - CVE-2026-31431

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

A fully featured Windows backdoor that uses email as a C&C server

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Reverse Shell Detection with Machine Learning

The FreeBSD ICMP buffer overflow, freebsd buffer overflow poc

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

Proof of concept python script for regreSSHion exploit.