
EDRaser
Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

Windows Oracle Database Attack Toolkit

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A collection of awesome security hardening guides, tools and other resources


CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

Customer Support System 1.0 - SQL Injection Vulnerability in manage_department.php via "id" URL Parameter