
NiCOFF
COFF and BOF Loader written in Nim

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

RPCとデバッグオブジェクトを悪用したUACバイパス

SubSeven Legacy Official Source Code Repository

CVE-2026-64638 — WordPress 認証前の反射型XSS → DOM Clobbering+アプリケーションパスワード窃取+REST APIプラグイン有効化によるRCE。デュアルモードPoC(XSSチェーンおよび直接攻撃)。

Windwos ゼロデイ ローカル権限昇格エクスプロイト (CVE-2026-41091)

Windows SQL Server に任意のマシンへの認証を強制する手法


ms-settings DelegateExecute レジストリキーを使用して Windows 10/11 x64 の UAC を回避します。

NETWORK SERVICE FAX Service におけるコード実行と永続化

ヘッドレスAggressorクライアントを(ほぼ)機能的なCobalt Strikeクライアントに変えるAggressorscript。

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJ…

システムコール実行時に任意のコールスタックを偽装するためのPoC実装(例:NtOpenProcessによるハンドル取得)

LDAPセッションの永続化、ACLの悪用、Kerberoasting/ASREProasting、シャドウ資格情報、RBCD、NTLMリレーを使用して、Active Directoryを列挙・攻撃します。

Windows向けに、ランタイムSSN解決を備えたシングルスタブによる直接的・間接的なシステムコーリング。

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely