
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

Perfom With Massive Authentication Bypass In PaperCut MF/NG

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

Script that automates the process of escalating privileges on openbsd system (CVE-2019-19520) by exploiting the xlock binary and againing it's sgid…

CVE-2026-46376 - FreePBX Unauthenticated UCP Access via Hard-Coded Credentials