
mimikatz
A little tool to play with Windows security

A little tool to play with Windows security

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

The most comprehensive authentication framework

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

web2py/web2py @ e94946d

LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Vulnerability Research

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

Serverless AITM Simulation Framework for Entra ID and M365


cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等

An authentication bypass using an alternate path or channel in Fortinet product

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.