
c-jwt-cracker
JWT brute force cracker written in C

JWT brute force cracker written in C

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI


Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…


Simple HS256, HS384 & HS512 JWT token brute force cracker.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Detect and abuse risky SPNs

Low and slow password spraying tool, designed to spray on an interval over a long period of time

Use ESC1 to perform a makeshift DCSync and dump hashes

Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻


PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.