
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

A Collection of Over 60 Scripts - updated specifically for the BadUSB function on the FlipperZero.

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…


Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

Extraction of iMessage Data via XSS

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version…

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks against multiple…