
mimikatz-missing-manual
Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…

Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…


Demos for the Blackhat USA 2022 talk "Taking Kerberos to the Next Level"

CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability

POC for CVE-2025-54918 and a technical demonstration.

Proof-of-concept exploit for PaperCut CVE-2023-27350, chaining authentication bypass with built-in scripting abuse to achieve remote code execution…

CentOS Control Web Panel, Root Privilege Escalation

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

Proof-of-concept exploit for CVE-2026-18963, a critical Keycloak reset-credentials bypass enabling unauthenticated account takeover. Includes lab…

This is poc of CVE-2022-46169 authentication bypass and remote code execution

TorChat - Secure, private, and anonymous peer-to-peer chat over the Tor network

CVE-2022-39227 : Proof of Concept

scanner/exploiter CVE-2026-24061 & CVE-2026-32746

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

Proof-of-concept exploit for CVE-2024-41107 targeting SAML authentication bypass in Apache CloudStack versions 4.5.0–4.18.2.1 and 4.19.0.0–4.19.0.2.