
CVE-2025-53770
Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner

Mirror moved — see GitHub and Codeberg

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Check for LDAP protections regarding the relay of NTLM authentication

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation


Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Pure-Nim network enumeration and remote execution toolkit for authorized security assessments. Supports SMB, LDAP, Kerberos, WinRM, database clients,…

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

SSH-MITM - ssh audits made simple

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.