
CVE-2019-17662
Golang implementation of CVE-2019-17662 TinyVNC Arbitrary File Read leading to Authentication Bypass Exploit

Golang implementation of CVE-2019-17662 TinyVNC Arbitrary File Read leading to Authentication Bypass Exploit

CVE-2025-58434 and CVE-2025-59528 chain POC

CVE-2024-56348 — JetBrains TeamCity <2024.12 auth bypass + RCE exploit (unauthenticated SYSTEM_ADMIN + shell)

CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript

RCE for WingFTP v4.7.3

bypass all stages of the password reset flow

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

Objective-C library and console to interact with Heimdal APIs for macOS Kerberos

Tool to spray AWS Console IAM Logins

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

A little tool to play with Windows security

Trying to tame the three-headed dog.

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

Powershell tool to automate Active Directory enumeration.

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

A little toolbox to play with Microsoft Kerberos in C

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

Tools for Kerberos PKINIT and relaying to AD CS