
vcenter_saml_login
A tool to extract the IdP cert from vCenter backups and log in as Administrator

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Perform a MitM attack and extract clear text credentials from RDP connections

Exploit for CVE-2018-14847 targeting MikroTik RouterOS to create a global proxy and extract credentials via PPTP server setup.

tool to extract passwords from TeamViewer memory using Frida

Exploit for CVE-2024-43044 enabling arbitrary file read from Jenkins controller to extract and decrypt credentials.xml using secret keys.

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Just a PoC tool to extract password using CVE-2019-1653.

An exploitation tool to extract passwords using CVE-2015-5995.

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

A python tool to automate KeePass discovery and secret extraction.

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies