
cormem-read-poc
This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Poc for CVE-2025-7771 to modify PPL Protection

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Kernel Process Termination Tool ( CVE-2026-0828 exploit)

A tool to automate the boring process of APK recon

An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer

An AWS IAM policy statement parser and query tool.

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Sigma rule for detecting exploitation of CVE-2022-30190 (Follina) via Windows process creation events, enabling SOC teams to identify malicious…