
CVE-2026-66804
Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

Code Execution & Persistence in NETWORK SERVICE FAX Service

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

IDA python script for deobfuscating Astaroth/Guildma injector DLL

AAD related enumeration in Nim

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package