
malicious-pdf
Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Automation for internal Windows Penetrationtest / AD-Security

Automating situational awareness for cloud penetration tests.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Pop shells like a master.

MSDAT: Microsoft SQL Database Attacking Tool

Python and Powershell internal penetration testing framework

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

Exploit Code for CVE-2020-1472 aka Zerologon

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities

Technical Reference to multiple relay techniques

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

An SDN penetration testing toolkit

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492