
cloudfox
Automating situational awareness for cloud penetration tests.

Automating situational awareness for cloud penetration tests.

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

Tool to discover external and internal network attack surface

ntlm relay attack to Exchange Web Services

Dominate the domain. Relay to royalty.

Automated scanner and exploit tool for CVE-2021-26855 targeting Microsoft Exchange servers, enabling remote code execution on vulnerable instances…

DoSinator is a powerful Denial of Service (DoS) testing tool developed in Python.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…

Remote Code Execution Exploit in the RPC Library

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

GitHub Actions Pipeline Enumeration and Attack Tool

Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

A DNS spoofer tool written in Python3.

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…