
Koh
Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

listmonk’s Session Persistence After Password Reset and Password Change

CVE-2025-8517: Session Fixation in Vvveb CMS v1.0.6.1

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

Apache Tomcat - Session fixation via rewrite valve

An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

CVE-2024-50562 is a session management vulnerability in Fortinet SSL-VPN portals

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

COFF file (BOF) for managing Kerberos tickets.

Zabbix - SAML SSO Authentication Bypass