
EasyTokens
Kali365 - EvilTokens Replica

Kali365 - EvilTokens Replica

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.



Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Python exploit that tests domain controllers for Zerologon (CVE-2020-1472) and resets the vulnerable machine account password through Netlogon…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Detect and abuse risky SPNs

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Use ESC1 to perform a makeshift DCSync and dump hashes

Proof-of-concept exploit for CVE-2026-25050, a timing attack enabling user enumeration via GraphQL authentication. Measures response times to…

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…