
Zetsu
A personal RAG system for offensive security knowledge

A personal RAG system for offensive security knowledge

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Offensive MSSQL toolkit written in Python, based off SQLRecon

Offensive tool to trigger network authentications as SYSTEM

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

This is An Offensive Hacking Tool which can be used by hackers and for penetration testing purposes. Hack Responsibly!!!!!!!

Collection of offensive techniques for attacking Windows environments, with practical methods for exploitation, privilege escalation, and adversarial…

Welcome to the Doggie and EvilDoggie repository by Faraday Security! Doggie is a modular DIY CAN Bus to serial adapter (USB, BLE, UART) using the…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Modular GCP attack toolkit for offensive research, enabling reconnaissance, authentication manipulation, and exploitation of cloud functions,…

SoK/Whitepaper on Offensive Operations against Active Directory Certificate Service

An offensive security researcher + an AI vs. a fresh n-day: building the first public PoC for CVE-2026-53435 in one Friday night. Raw 8h20m log…

Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…