
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Relational database brute force and post exploitation tool for MySQL and MSSQL

Automated NoSQL database enumeration and web application exploitation tool.

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Blind SQL injection tool for automated database schema enumeration and data extraction. Supports 20+ database engines with evasion techniques for WAF…

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Blind SQL injection exploit for ZoneMinder (CVE-2024-51482) with time-based extraction, database enumeration, and credential dumping capabilities.

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

CVE-2026-44680 exploit framework for MikroORM SQL injection. Detects and exploits JSON path injection vulnerabilities with UNION-based and blind data…

Exploit for CVE-2025-5878 targeting ESAPI's encodeForSQL() method with OracleCodec, enabling time-based blind SQL injection. Supports database…

RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Proof-of-concept exploit for CVE-2024-51482, a boolean-based SQL injection in ZoneMinder, enabling database enumeration and credential extraction.

Proof-of-concept exploit for CVE-2023-31714, a pre-authentication SQL injection in Chitor-CMS < 1.1.2. Automates database enumeration and credential…

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Proof-of-concept exploit for CVE-2019-10708 SQL injection vulnerability in SCMS, with multiprocessing support for database enumeration and admin…

Proof-of-concept exploit for CVE-2025-2011, a SQL injection vulnerability in WordPress Depicter Plugin 3.6.1, enabling database enumeration and data…

Security assessment and post-exploitation toolkit for Microsoft SQL Server with enumeration, privilege escalation, code execution, lateral movement,…