Bug D payload host

Private research payloads for authorized reproduction of the VMware Workstation HGFS guest-to-host escape. All benign: each only writes a marker file on the host.

Defender note. Only lowrun2.exe (the AppContainer confinement launcher) trips Defender's ML heuristic Trojan:Win32/Wacatac.B!ml - a false positive on its token/AppContainer API pattern. It is kept out of the default download and provided encrypted + as source.

FileDefender on downloadExtract with
vmpwn-payloads.zipclean (no lowrun2.exe)in-box tar -xf
vmpwn-exe.zipclean (guest-read, hostmark, lowrun)in-box tar -xf
vmpwn-full.7zpasses (AES-256 encrypted, unscannable)7zr.exe x -pinfected
7zr.execlean (7-Zip standalone)-
lowrun2.cclean (source)compile in lab
vmpwn-poc.batclean (.bat, cmd-only)run in the guest
SHA256SUMS.txtchecksums-

Encrypted archive password: infected. The escape itself needs none of the EXEs - it is cmd.exe + the .bat/.json files, all clean.