
evil-winrm
The ultimate WinRM shell for hacking/pentesting

The ultimate WinRM shell for hacking/pentesting

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

A tool that implements the Golden SAML attack

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

C# tool for Kerberos protocol manipulation, enabling ticket requests, delegation (S4U), kerberoasting, AS-REP roasting, and golden/silver ticket…

A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml

Proof-of-concept exploit for CVE-2024-29855, an authentication bypass in Veeam Recovery Orchestrator. Includes JWT token spraying and technical root…

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

Proof-of-concept exploits for Apache OfBiz vulnerabilities (CVE-2024-32113, CVE-2024-36104, CVE-2024-38856) demonstrating remote code execution and…

PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

WordPress Mobile builder Plugin <= 1.4.2 is vulnerable to a high priority Broken Authentication

Shell-based exploit for CVE-2025-31161, an authentication bypass in CrushFTP that allows unauthenticated attackers to forge CrushAuth tokens and…

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover