
evilginx
PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO

COFF file (BOF) for managing Kerberos tickets.

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

Zabbix - SAML SSO Authentication Bypass

Post-Exploitation EVTX Analyzer for BloodHound Mapping

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A small PoC for the Keycloak vulnerability CVE-2023-0264

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

listmonk’s Session Persistence After Password Reset and Password Change

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability