
copyfail-rs
Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Hardened NixOS-based operating system with ANSSI-compliant security policies, TPM2/Yubikey authentication, full-disk encryption, Secure Boot…

Automated Linux hardening script that configures firewalls, malware scanners, system auditing, and network security controls across major…

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

Automates Windows domain Kerberos relay attacks to achieve local privilege escalation via RBCD, Shadow Credentials, or ADCS web enrollment, then…

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

Abuses Kerberos tickets to bypass Windows UAC and gain SYSTEM privileges by injecting a fake MachineID into service tickets, leveraging the tgtdeleg…

Windows tool for extracting Kerberos tickets from the LSA cache, supporting SYSTEM impersonation, session discovery, and targeted ticket dumping for…

Standalone SSH server for Windows with pubkey authentication, clipboard sharing, and system tray integration. Supports remote command execution and…

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Industrial-grade secure snippet warehouse for your system tray. 📦 Built with Rust (Tauri v2) & React. Offline-first, AES-256 encrypted, and…

Windows RPC-based SYSTEM authentication trigger for relaying attacks against ADCS and LDAP, enabling privilege escalation and lateral movement on…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

Modern C SSH/TELNET bulletin board system with AI-moderated chat, retro BBS features, file transfers, RSS reader, and JSON automation API. Supports…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code