
ROADtools
A collection of Azure AD/Entra tools for offensive and defensive security purposes

A collection of Azure AD/Entra tools for offensive and defensive security purposes

LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

Vulnerability Research

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

A attempt at cryptographic framework for Baochip-1x .

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…



Serverless AITM Simulation Framework for Entra ID and M365

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

Modules used by the Havoc Framework

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

An authentication bypass using an alternate path or channel in Fortinet product

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager