
Chrome-App-Bound-Encryption-Decryption
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

Freedom Fighting Mode: open source hacking harness

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…

Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.

Azure Post Exploitation Framework

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

WIP Post-exploitation framework tailored for hypervisors.

Arbitrary File Read and DoS in vendure-ecommerce exploit



CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit