
AADInternals
PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

User enumeration and password spraying tool for testing Azure AD

Proof-of-concept exploit for CVE-2020-1958, an LDAP injection vulnerability in Apache Druid 0.17.0, enabling user enumeration and LDAP attribute…

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Python tool to exploit CVE-2021-26855 (ProxyLogon) for downloading Exchange mailbox emails via EWS, supporting user enumeration and bulk target…

Bash script for WordPress user enumeration and automated admin account creation, exploiting CVE-2026-23550 to bypass authentication and achieve…

Python exploit for CVE-2019-9053 SQL injection in CMS Made Simple 2.2.10 with password hash cracking and user enumeration capabilities.

WordPress pentest tool

An LDAP based Active Directory user and group enumeration tool

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.

PoC exploit for CVE-2021-26855 (Exchange Server SSRF) with user enumeration, mail header reading, and vulnerability detection. Supports…

Automated auth bypass exploit for CVE-2025-0316 targeting WordPress WP Directorybox Manager. Features user enumeration, proxy support,…

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

Kerberos-based password spraying framework for Active Directory with built-in lockout prevention, user enumeration integration, recursive password…