
AD-PathFinder
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows…

Automatic SQL injection and database takeover tool

🐶 A curated list of Web Security materials and resources.

Automated All-in-One OS Command Injection Exploitation Tool

File upload vulnerability scanner and exploitation tool.

A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying…

XSS payloads designed to turn alert(1) into P1

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.


Information and PoC about the ENLBufferPwn vulnerability

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

Offensive MSSQL toolkit written in Python, based off SQLRecon

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

Technical Reference to multiple relay techniques

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.