
ADCSync
Use ESC1 to perform a makeshift DCSync and dump hashes

Use ESC1 to perform a makeshift DCSync and dump hashes

Protocol agnostic online password guessing API.

Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)

Advisory for CVE-2026-77771, a 2FA bypass in the miniOrange WordPress plugin via session-scoped OTP lockout, with impact analysis and remediation…

This is the exploit of CVE-2019-17240.

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain…

Detects NTLM authentication status by checking LmCompatibilityLevel registry value to assess exposure to CVE-2024-43451 and mitigate credential relay…

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

WPBF - a multithreaded WP brute forcer

elabFTW < 4.1.0 - account lockout bypass and login brute force

POC for CVE-2024-3183 (FreeIPA Rosting)

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

CVE-2023-1665 - Twake App


Detect and abuse risky SPNs

Fast offline auditing of Active Directory passwords using Python.