
Ghost-In-The-Logs
Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Evade EDR's the simple way, by not touching any of the API's they hook.


A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Git Web Hook Tunnel for C2

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

Local PoC for CVE-2026-54686 demonstrating DCS lifecycle hook spoofing in Warp terminal. Simulates spoofed CWD and SSH metadata acceptance in…

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Hook PasswordChangeNotify

hook repo for cve-2024-32002

CVE-2025-10230 PoC - Samba WINS Hook Command Injection

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

RCE hook

Working Python test and PoC for CVE-2018-11776, includes Docker lab

An ssh honeypot with the XZ backdoor. CVE-2024-3094