
CVE-2023-2732
Perform With Massive Authentication Bypass (Wordpress Mstore-API)

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

Tool to spray AWS Console IAM Logins

Audit and incident response tool for CVE-2026-41940 vulnerability

Password Lense: reveal character types in a password

A tool for checking if MFA is enabled on multiple Microsoft Services

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

Exploit tool for CVE-2022-1162 that enumerates GitLab users and performs authentication bypass via a crafted login request.

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

Python3 tool to perform password spraying using RDP

Perform a MitM attack and extract clear text credentials from RDP connections

Proof of concept for CVE-2015-0006. Fixed in MS15-005 https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-005 .

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via crafted X-Forwarded-For headers and anti-CSRF tokens to evade sshguard…

ADCS cert template modification and ACL enumeration

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…

Retrieve AD accounts description and search for password in it