#1Tools for maintaining access, exploring, and expanding control within compromised systems and networks.
Kitploit recommended

A modification to fortra's CVE-2023-28252 exploit, compiled to exe

LPE PoC of a vulnerability in the io_uring subsystem of the Linux Kernel.

A SOCKS proxy for Citrix.

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

CVE-2022-2602

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Default Detections for EDR

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Registry permission scanner written in C# for finding potential privesc avenues within registry

Source Code Management Attack Toolkit

POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a…

Implements the POP/MOV SS (CVE-2018-8897) vulnerability by bugchecking the machine (local DoS).

Research of CVE-2014-3153 and its famous exploit towelroot on x86

Proof of concept of LibreOffice remote arbitrary file disclosure vulnerability

A host based IDS written in C# Targetted at Metasploit

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…