
security-research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

Security Research from the Microsoft Security Response Center (MSRC)

A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

DHCP exhaustion script written in python using scapy network library

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Script to identify hosts vulnerable to CVE-2018-10933

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

PrintNightmare (CVE-2021-34527) PoC Exploit

VOIP Security Audit Framework

Exploit and Check Script for CVE 2022-1388

Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.


There are many cheat sheets out there, but this is mine.

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.