
CVE-2024-5764
Python script to decrypt data encrypted by the Java PasswordCipher class, exploiting CVE-2024-5764's static encryption key in Sonatype Nexus…

Python script to decrypt data encrypted by the Java PasswordCipher class, exploiting CVE-2024-5764's static encryption key in Sonatype Nexus…

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

Proof-of-concept demonstrating bypass of TPM-bound LUKS disk encryption on Linux systems, extracting volume keys via custom root filesystem attack.

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

Portable zipfile extraction utility with broad OS support, decryption, and security fixes for path traversal and symlink vulnerabilities.

Private keys generated with vulnerable keypair versions (CVE-2021-41117)

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

Resources and PoCs

Portable binary distribution of xz-utils 5.8.3 with CVE-2024-3094 verification. Provides static builds for Linux, macOS, and Windows for compression…

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

Exploit for cve-2013-0169

Exploitation toolkit for CVE-2025-59287 RCE in WSUS. Includes AES payload encryption and an exploitation module for authorized penetration testing.

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

Updated version of this weak password encryption script

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.

Exploit for AMD SEV-SNP firmware vulnerability CVE-2024-21978, enabling decryption of arbitrary guest memory via memory corruption of context pages.

An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all…