
tiandy-research
This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Python version of the C# tool for "Shadow Credentials" attacks

Tool to spray AWS Console IAM Logins


Proof of concept for CVE-2015-0006. Fixed in MS15-005 https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-005 .

Active Directory password filter featuring breached password checking and custom complexity rules

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

PoC for login with password hash in STARFACE

Zeek detection logic for CVE-2022-30216.

Exploit for CVE-2023-7028 - GitLab CE/EE

Dump Kerberos tickets from the KCM database of SSSD


Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…