
totp-ssh-fluxer
Take security by obscurity to the next level (this is a bad idea, don't really use this please)

Take security by obscurity to the next level (this is a bad idea, don't really use this please)

mcp-remote exposed to OS command injection

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Abusing Azure services over C2

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

Collection of tools to use with Azure Applications

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.

Step-by-step analysis of CVE-2022-46169: unauthenticated remote code execution in Cacti via authentication bypass and command injection, with Docker…

An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…


A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks.