
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Manual black-box penetration test of hosting provider infrastructure using curl_cffi and Python. Identifies exposed databases, default credentials,…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Security assessment and post-exploitation toolkit for Microsoft SQL Server with enumeration, privilege escalation, code execution, lateral movement,…

Modular penetration testing tool for Microsoft SQL Server that automates credential discovery, privilege escalation, command execution, and data…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

PoC exploit for CVE-2021-22146 that dumps Elastic ECE databases (versions 7.10.0 to 7.13.3) during internal penetration tests.

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…