
FiberBreak
React2Shell Exploitation Tool (CVE-2025-55182)

React2Shell Exploitation Tool (CVE-2025-55182)
A toolkit to attack Office365

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Scan for open S3 buckets and dump

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Azure Post Exploitation Framework

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

A proof of concept demonstrating the use of Google Drive for command and control.

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

Cloud Storage using Instagram.

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.