
pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.

Penetration tests guide based on OWASP including test cases, resources and examples.

The ultimate WinRM shell for hacking/pentesting

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

A tool that implements the Golden SAML attack

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

Collection of tools to use with Azure Applications

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)

Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)

A little tool to play with Kerberos.

A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml

PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…


Lightweight Python library for obfuscating JWT payload values using XOR encryption with timestamp-based keys, preventing plaintext decoding of…