
Chrome-App-Bound-Encryption-Decryption
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

Proof-of-concept exploit for CVE-2018-4084, a WiFi credential leak vulnerability in macOS High Sierra, demonstrating interception of plaintext Wi-Fi…

Toolkit for attacking MS Kerberos implementations: extract SPN accounts, request and export tickets, crack service passwords, rewrite tickets for…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

tool to extract passwords from TeamViewer memory using Frida

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Proof-of-concept exploit for CVE-2018-14847 allowing arbitrary file read of plaintext passwords from MikroTik RouterOS WinBox service, with TCP/IP…

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords

An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all…

Creates Active Directory machine accounts with custom passwords, supporting optional OU placement, explicit credentials, and UAC flag configuration.

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

Script in Ruby. Break Remote router wifi passwords.

An exploitation tool to extract passwords using CVE-2015-5995.

Decrypts Grafana DataSource passwords by exploiting CVE-2021-43798 directory traversal to retrieve configuration files and derive encryption keys.

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning…