
AD-PathFinder
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Self-developed tools for Lateral Movement/Code Execution

Windows privilege escalation tool exploiting SeImpersonate privileges via Named Pipe impersonation, supporting multiple execution methods…


Offensive MSSQL toolkit written in Python, based off SQLRecon

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

mssql 终端连接工具|命令执行



PoC CVE

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit