
CVE-2026-8181-PoC
Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

A Python package and CLI for parsing aggregate and forensic DMARC reports

A tool for checking if MFA is enabled on multiple Microsoft Services

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

Enumerate information from NTLM authentication enabled web endpoints 🔎

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

Proof-of-concept for Active Directory username enumeration vulnerability in Hyland OnBase via login endpoint response differences, enabling…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.