
fyp
Desktop-based vulnerability assessment tool for security teams — scan web apps & networks, detect CVEs, map exploits, auto-score risk, and generate…

Desktop-based vulnerability assessment tool for security teams — scan web apps & networks, detect CVEs, map exploits, auto-score risk, and generate…
Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

CVE-2025-40554 Exploitation

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

User enumeration and password spraying tool for testing Azure AD

A tool for secrets management, encryption as a service, and privileged access management

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

Tool for Active Directory Certificate Services enumeration and abuse

A tool for checking if MFA is enabled on multiple Microsoft Services

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

C# tool for automated password spraying attacks against Active Directory users via LDAP, with configurable delays and password lists, designed for…

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)