
CVE-2021-21239
Exploit for CVE-2021-21239: SAML signature validation bypass in pysaml2/Redash. Forges SAML responses with embedded public keys to impersonate users…

Exploit for CVE-2021-21239: SAML signature validation bypass in pysaml2/Redash. Forges SAML responses with embedded public keys to impersonate users…

The cryptography-based networking stack for building unstoppable networks with LoRa, Packet Radio, WiFi and everything in between.

Advisory and technical write-up for CVE-2026-18782, a critical SQL injection in TREX MES web API endpoints enabling auth bypass, data theft, and RCE…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Trying to tame the three-headed dog.

Kerberos relaying and unconstrained delegation abuse toolkit

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Dominate Active Directory with PowerShell.

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

Windows Privilege Escalation from User to Domain Admin.

Tools for Kerberos PKINIT and relaying to AD CS

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

DCOM in memory and fileless lateral movement techniques through .Net deserilization