
aad-sso-enum-brute-spray
POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit


credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

POC of CVE-2022-36537

Asymmetric cryptography library for generating signed URLs on embedded devices, enabling time-limited resource access using PSA Crypto API with…

Exploit for the CVE-2024-5806




Zero-Trust SSH CA