
WMIExec
Set of python scripts which perform different ways of command execution via WMI protocol.

Set of python scripts which perform different ways of command execution via WMI protocol.

Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).

Proof-of-concept demonstrating a command injection vulnerability in MS-Agent Shell tool, enabling arbitrary command execution and reverse shell via…

Python port of the Linksys tmUnblock.cgi RCE exploit

Offensive MSSQL toolkit written in Python, based off SQLRecon

CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.

Python proof-of-concept for unauthenticated OS command injection in TOTOLINK N600R, exploiting the langType parameter to execute arbitrary commands…

Python proof-of-concept for CVE-2025-54123, demonstrating command injection to RCE in Hoverfly middleware API with credential or token-based…

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

Python and Powershell internal penetration testing framework

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)

Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing.