
CVE-2025-62215
Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Generates header/ASM files for direct Windows system calls to bypass AV/EDR user-mode hooks, enabling stealthy code execution and evasion in red team…

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Generates header/ASM files for direct Windows system calls to bypass user-mode API hooks used by AV/EDR products, enabling stealthy red team…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

HTTP-based remote access tool with DLL injection, process hollowing, and system hooking for persistent control, screen monitoring, file exfiltration,…

Single-file Windows exploit for CVE-2019-0708 (BlueKeep) that executes a reverse shell with SYSTEM privileges via RDP, statically compiled with…

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

PoC for popping a system shell against the LnvMSRIO.sys driver

Proof-of-concept exploit for CVE-2019-9729, a heap underflow in SdoKeyCrypt.sys driver enabling local privilege escalation to SYSTEM shell on Windows…

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

Proof-of-concept exploit for CVE-2025-29824, a use-after-free vulnerability in the Windows CLFS kernel driver, demonstrating privilege escalation to…

With the help of this docker image, you can easily access PEzor on your system!

Python exploit for CVE-2022-40471: remote code execution via unrestricted file upload in Clinic's Patient Management System. Uploads a PHP webshell…