
PowerPriv
A Powershell implementation of PrivExchange designed to run under the current user's context

A Powershell implementation of PrivExchange designed to run under the current user's context

CPL remote trigger

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

Automated exploitation tool targeting CMS vulnerabilities in Joomla, WordPress, Drupal, PrestaShop, and OsCommerce with built-in brute-force and…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…


CVE-2019-0708 Exploit

SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

Tools for Kerberos PKINIT and relaying to AD CS

SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environments.

Proof-of-concept exploit for CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration Suite via zimbra-snmp log injection,…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

xll windows reverse shell