
CVE-2021-26088
PoC for CVE-2021-26088 written in PowerShell

PoC for CVE-2021-26088 written in PowerShell

POC for CVE-2024-10924 written in Python

Perform a MitM attack and extract clear text credentials from RDP connections

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

JWT brute force cracker written in C

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

A fast enumeration tool for Windows Active Directory Pentesting written in Go

POC for CVE-2018-0114 written in Go

A JWT based API for managing users and issuing JWT tokens

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

LDAP Querying without the Suck

Active Directory password spraying tool. Auto fetches user list and avoids potential lockouts.


Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…