
Shadow-Vault
Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Detection artifact generator for SolarWinds Web Help Desk pre-auth RCE chain (CVE-2025-40552 + CVE-2025-40553). Verifies authentication bypass and…

A tool for secrets management, encryption as a service, and privileged access management

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

POC tool for ResetNightmare (CVE-2026-27912)

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

A terminal based tool for managing secrets with both tui and cli support

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

A simple and secure command-line tool for managing TOTP-based two-factor authentication codes.

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…