
TokenTactics
Azure JWT Token Manipulation Toolset

Azure JWT Token Manipulation Toolset

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Proof-of-concept exploit for CVE-2024-47066, a server-side request forgery (SSRF) vulnerability in LobeChat that bypasses IP-based restrictions via…

Proof-of-concept exploit for CVE-2026-44578, a Server-Side Request Forgery in Next.js WebSocket upgrade handler. Includes detection mode and…

Automated network asset, email, and social media profile discovery and cataloguing.

Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)

PowerShell-based security assessment framework for Microsoft 365, Azure, and Entra ID. Scans for misconfigurations, CIS benchmark compliance, and…

XML External Entity PoC in an S3.

automated password spraying tool

Bash-based exploit script for CVE-2025-9074 that abuses the internal Docker API to mount the host C drive, execute commands inside a container, and…

A fork of the great TokenTactics with support for CAE and token endpoint v2

Non-destructive detector for CVE-2026-31431 (Copy Fail) local privilege escalation in XCP-ng 8.3 Dom0, validating kernel vulnerability via page-cache…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Kubernetes-native security operator that automates vulnerability scanning, configuration auditing, secret detection, RBAC analysis, and compliance…

PacBot (Policy as Code Bot)

A tool that can help detect and takeover subdomains with dead DNS records