News
DOG - Data Only Gadgets
What is DOG? DOG, short for Data Only Gadgets, is a post-exploitation tool that uses your existing kernel read/write primitives to locate, classify, and chain kernel gadgets, resolve the structures...
DOG - Data Only Gadgets
What is DOG? DOG, short for Data Only Gadgets, is a post-exploitation tool that uses your existing kernel read/write primitives to locate, classify, and chain kernel gadgets, resolve the structures...
"The Watchdog" in Control Pack
We have noticed in many post-exploitation frameworks that persistence access is a recurring weakness. The issue remains by design in their single-process execution model. This could become a real problem...
"The Watchdog" in Control Pack
We have noticed in many post-exploitation frameworks that persistence access is a recurring weakness. The issue remains by design in their single-process execution model. This could become a real problem...
Exploit Pack featured in HVCK Magazine
Check out our Technical Training Courses on Windows Kernel Exploitation --- Exploit Pack and its founder, Juan Sacco (LinkedIn), were featured in the latest edition of HVCK Magazine. The article focuses...
Exploit Pack featured in HVCK Magazine
Check out our Technical Training Courses on Windows Kernel Exploitation --- Exploit Pack and its founder, Juan Sacco (LinkedIn), were featured in the latest edition of HVCK Magazine. The article focuses...
Bypassing Kernel Code Execution: SSDT Hijack Un...
By Juan Sacco (LinkedIn), founder of Exploit Pack. Check out our Technical Training Courses on Windows Kernel Exploitation --- I have always been interested in Windows Kernel Exploitation, but this...
Bypassing Kernel Code Execution: SSDT Hijack Un...
By Juan Sacco (LinkedIn), founder of Exploit Pack. Check out our Technical Training Courses on Windows Kernel Exploitation --- I have always been interested in Windows Kernel Exploitation, but this...
Suspended threads in Windows 11 25h2 with VBS/HVCI
Check out our Technical Training Courses on Windows Kernel Exploitation --- Arbitrary Code Execution achieved in Windows 11 25h22 with VBS/HVCI present via a R/W data attack abusing suspended threads.Based on the...
Suspended threads in Windows 11 25h2 with VBS/HVCI
Check out our Technical Training Courses on Windows Kernel Exploitation --- Arbitrary Code Execution achieved in Windows 11 25h22 with VBS/HVCI present via a R/W data attack abusing suspended threads.Based on the...
Data Only attack using [Superfetch] + RDMSR Inf...
Check out our Technical Training Courses on Windows Kernel Exploitation --- Windows Kernel data-only manipulation attacks with VBS/HVCI using Superfetch and L_STAR (rdmsr) for https://exploitpack.comUser-mode and Kernel code runs in VTL0...
Data Only attack using [Superfetch] + RDMSR Inf...
Check out our Technical Training Courses on Windows Kernel Exploitation --- Windows Kernel data-only manipulation attacks with VBS/HVCI using Superfetch and L_STAR (rdmsr) for https://exploitpack.comUser-mode and Kernel code runs in VTL0...