
RelayKing-Depth
Dominate the domain. Relay to royalty.

Dominate the domain. Relay to royalty.

Scans Active Directory domain controllers for CVE-2021-42287 and CVE-2021-42278 by querying DNS for all DCs and analyzing PAC structures for the 0x10…

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain…

Python script using Impacket to test domain controllers for the Zerologon vulnerability (CVE-2020-1472) via Netlogon authentication bypass, with…

Python script to test domain controllers for CVE-2020-1472 (Zerologon) using Impacket. Performs Netlogon authentication bypass detection with minimal…

LSTAR - CobaltStrike Translated to EN

Zeek package for detecting CVE-2020-1350 (SIGRed) Windows DNS server exploit attempts via large DNS SIG/KEY response analysis with configurable…

Payload Generation Framework

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Zeek package detecting CVE-2022-30216 NTLM relay attacks against Windows Server. Raises notices for exploit attempts and successful exploitation via…

CVE-2021-1675 Detection Info

Proof-of-concept Denial of Service exploit for CVE-2020-1350 (SIGRed) targeting Windows DNS servers via crafted DNS SIG records. Includes PCAP for…

Scans and exploits CVE-2024-6387 (regreSSHion) in OpenSSH servers. Features multi-threaded scanning, banner retrieval, grace time detection, and…

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

Proof-of-concept exploit for CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration Suite via zimbra-snmp log injection,…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…