
Koh
Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

COFF file (BOF) for managing Kerberos tickets.

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

The DCERPC only printerbug.py version

Opens 1K+ IPs or Shodan search results and attempts to login

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

Find authentication (authn) and authorization (authz) security bugs in web application routes.

LDAP Querying without the Suck

F5 BIG-IP RCE exploitation (CVE-2022-1388)


Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)

Azure AD Password Checker

Facebook brute forcer script


Post-Exploitation EVTX Analyzer for BloodHound Mapping