
staged-DLL-Injection-SMB-
Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

Activation Context Hijacking Evasion Tool

Memory API proxy via signed mozglue.dll

DLL Hijacking in Quickheal Total Security/ Internet Security/ Antivirus Pro (Installers)


Microsoft Office / COM Object DLL Planting

PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527

this tool can generate a exp for cve-2017-8486, it is developed by python

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…


A desktop tool that allows injecting DLLs, hooking WinAPI functions like CreateFileW, and modifying process behavior at runtime — designed for…

Two versions of CVE-2017-8759 exploits

C# PrintNightmare (CVE-2021-1675)

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

DLL Planting in the Corsair iCUE v.5.3.102 CVE-2023-38822

DLL Planting in the CoD MW Warzone 2 - CVE-2023-38821

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation