Skip to content
View st3rven's full-sized avatar
💭
💭

Block or report st3rven

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

exploits 🗡️

35 repositories

Exploit for CVE-2023-36802 targeting MSKSSRV.SYS driver

C 112 26 Updated Oct 26, 2023

Shellcode reflective DLL injection in Rust

Rust 26 2 Updated Jun 24, 2025

Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user

Python 1,033 193 Updated Jul 10, 2022

SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection support.

C# 441 47 Updated May 16, 2024
Python 194 23 Updated Aug 17, 2022

Proof-of-Concept for CVE-2023-38146 ("ThemeBleed")

C# 201 37 Updated Sep 13, 2023

POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.

Python 126 20 Updated Jul 12, 2024

PoC - Authenticated Remote Code Execution in VMware vCenter Server (Exploit)

Python 44 7 Updated Jul 16, 2024

POC for CVE-2024-40348. Will attempt to read /etc/passwd from target

Python 32 7 Updated Jul 21, 2024

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

Python 1,266 282 Updated Nov 3, 2020

Exploit targeting NT kernel in 24H2 Windows Insider Preview

C 147 28 Updated Apr 26, 2024

A tool to abuse Exchange services

Go 2,287 365 Updated Jun 10, 2024

Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.

C 1,217 211 Updated Nov 7, 2025

A delicious, but malicious SSL-VPN server 🌮

Python 256 31 Updated Oct 2, 2025

Kerberos relaying and unconstrained delegation abuse toolkit

Python 1,481 217 Updated Jan 27, 2025

Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , CVE-2024-38473 , CVE-2023-38709

Python 116 16 Updated Oct 5, 2024

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises fr…

Python 93 31 Updated Dec 20, 2024

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Python 507 117 Updated Jan 2, 2025

An implementation of PSExec in C#

C# 335 62 Updated Dec 1, 2020
Python 94 10 Updated Jan 16, 2025

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

C 301 47 Updated Jul 16, 2025

POC exploit for CVE-2024-49138

C++ 265 61 Updated Feb 14, 2025

IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - …

Go 88 14 Updated May 6, 2025

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

24 1 Updated Feb 5, 2025

POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY

C++ 225 35 Updated Apr 12, 2025

CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

Python 386 63 Updated Mar 20, 2025

CVE-2025-29927 Proof of Concept

TypeScript 94 28 Updated Mar 23, 2025

WinRAR 0day CVE-2025-8088 PoC RAR Archive

44 12 Updated Aug 12, 2025