
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Web vulnerability scanner written in Python3

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.


Db Database Assessment Tool

remote code execute for redis4 and redis5

Extract a slice of your production database to reproduce bugs locally. Point dbslice at a record, it follows foreign keys and gives you a complete,…

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.


OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

jackson unserialize

Analysis and reproduction of CVE-2025-57833

CVE-2025-14847 (MongoBleed)

Post-auth RCE exploit for ArcadeDB via JavaScript trigger GraalVM sandbox escape, executing OS commands over HTTP API with reverse shell or blind…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.