
OneLogicalMyth_Shell
A HTA shell to assist with breakout assessments.

A HTA shell to assist with breakout assessments.

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

Machine Learning Network Share Password Hunting Toolkit

Extraction of iMessage Data via XSS

WIP Post-exploitation framework tailored for hypervisors.

ActionScript Proof of Concept to perform cross-domain reads

A standalone Blind XSS Script.

Scan for open S3 buckets and dump

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

telegram bug that discloses user's hidden phone number (still unpatched) (exploit included)

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers

HiddenSteps — a local-first personal workflow intelligence platform

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…