
CVE-2018-19131
Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Curated penetration testing wiki with daily-updated techniques, scripts, and checklists for reconnaissance, web, cloud, mobile, and…

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

kernel privilege escalation enumeration and exploitation framework

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on…

Exploits Microsoft Exchange ProxyNotShell vulnerabilities (CVE-2022-41040 and CVE-2022-41082) with an authenticated PoC script that executes commands…

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

Chrome extension and Shodan scanner for detecting and demonstrating RCE vulnerabilities in React Server Components (RSC) and Next.js applications,…

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Proof-of-concept BYOVD exploit targeting kprocesshacker.sys driver to kill or suspend processes with kernel-level privileges on Windows systems.

Proof-of-concept exploits for critical SharePoint RCE vulnerabilities (CVE-2024-38094, CVE-2024-38024, CVE-2024-38023) with demonstration video.