0x02 // Open Source
github.com/oxfemale →rop_scanner
Gadget scanner that finds ROP gadgets inside any Windows DLL
CVE-2026-20817
Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.
LogonCredentialsSteal
LOCAL AND REMOTE HOOK msv1_0!SpAcceptCredentials from LSASS.exe and DUMP DOMAIN/LOGIN/PASSWORD IN CLEARTEXT to text file.
PoC_kernel_NULL_pointer_clfs.sys
PoC: Kernel NULL Pointer Dereference in clfs.sys
CVE-2026-2636_PoC
**CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger an unrecoverable system state by calling the…
ALPC_API_Client_Server
This small project demonstrates inter-process communication on Windows using the Advanced Local Procedure Call (ALPC) native APIs (NtAlpc*).
PPLControl_shells
native Windows utility for experimenting with and managing Protected Process (PP) and Protected Process Light (PPL) protections on modern Windows (Windows 10/11 and compatible Server builds).…
com_inject_cmd_lsass
Process Injection via Component Object Model (COM) IRundown::DoCallback() for run cmd.exe from lsass.exe or other pids
wasm_plugins
Wasm Crypto Plugins for cpp project with async crypto keys