
gimmepatz
Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

This is a toolkit that uses CVE-2024-31317 to extract private app data via ADB or spawn a shell with an app's UID.

A python based tool for exploiting and managing Android devices via ADB

Universal Dynamic Virtual Channel connector for Remote Desktop Services

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

Transparent file encryption in git

The next generation encrypted file sharing project

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to…

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability