
CVE-2026-35616
Detection toolkit for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Includes Python scanner and Nmap NSE script for identifying…

Detection toolkit for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Includes Python scanner and Nmap NSE script for identifying…

The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.


Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Penetration tests guide based on OWASP including test cases, resources and examples.

Mind-Maps of Several Things

A tool to perform Kerberos pre-auth bruteforcing

Perform a MitM attack and extract clear text credentials from RDP connections

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

A tool for checking if MFA is enabled on multiple Microsoft Services

SSH-MITM - ssh audits made simple

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Powershell tool to automate Active Directory enumeration.

PowerShell MachineAccountQuota and DNS exploit tools

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷