
ShadowSteal
Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation

Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Remote Desktop Protocol in Twisted Python

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

global rate-limiting in Linux (CVE-2016-5696) scanner

Bash-based exploit script for CVE-2025-9074 that abuses the internal Docker API to mount the host C drive, execute commands inside a container, and…

Automatic execution Payload From Windows By Path Users All Exploit Via File bashrc

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

Go implementation of the PwnKit Linux Local Privilege Escalation exploit (CVE-2021-4034)

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

Automated Outlook account registration tool using pure HTTP protocol with PerimeterX captcha solving, proxy pool management, and email token…

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

Learn how I found my first two CVEs by pure accident.

Pure Rust proof-of-concept for CVE-2026-31431, targeting Linux x86_64 kernels with AF_ALG AEAD support. Static musl build, no runtime dependencies,…

Pure PQC two-tier PKI hierarchy using ML-DSA-65 (NIST FIPS 204) on EJBCA Community Edition — Root CA + Sub CA with CRL and OCSP

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)