
dc-sonar
Analyzing AD domains for security risks related to user accounts

Analyzing AD domains for security risks related to user accounts

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-54121

A proof of concept exploiting CVE-2022-26923.

Exploitation for CVE-2024-49019

Automated CVE-2022-26923 Exploitation (Certifried)

Exploitation for CVE-2022-26923

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

Active Directory Lab for Penetration Testing

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services

Proof-of-concept for CVE-2025-60654: stored cross-site scripting (XSS) in Script Pag ad description field. Demonstrates filter bypass using HTML tags…

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

Educational analysis of CVE-2023-4863 (libwebp heap buffer overflow) with Blue Team detection tools, static WebP scanner, defensive Java validator,…