
Claude-Red
Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

Exploitation de CVE-2022-26923

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

Exploitation for CVE-2024-49019

Analyzing AD domains for security risks related to user accounts

Active Directory Lab for Penetration Testing

Educational analysis of CVE-2023-4863 (libwebp heap buffer overflow) with Blue Team detection tools, static WebP scanner, defensive Java validator,…

Exploitation for CVE-2022-26923

CVE-2026-54121

Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

Automated CVE-2022-26923 Exploitation (Certifried)

Proof-of-concept for CVE-2025-60654: stored cross-site scripting (XSS) in Script Pag ad description field. Demonstrates filter bypass using HTML tags…