


Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.


This skill helps Claude write secure code and prevent common vulnerabilities.

Fast and secure initramfs generator

A high-speed covert tunnel that disguises TCP traffic as SMTP email communication to bypass Deep Packet Inspection (DPI) firewalls.

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…


A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

An LDAP based Active Directory user and group enumeration tool

PoC Exploit for the NTLM reflection SMB flaw.

Python library for auditing Microsoft Active Directory via LDAP, supporting NTLM, Kerberos, SSPI authentication, channel binding, encryption, and…

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)