
Masky
Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory

Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

Perfom With Massive Authentication Bypass In PaperCut MF/NG

Script that automates the process of escalating privileges on openbsd system (CVE-2019-19520) by exploiting the xlock binary and againing it's sgid…


g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

CVE-2026-46376 - FreePBX Unauthenticated UCP Access via Hard-Coded Credentials