
MultiPotato
Windows privilege escalation tool exploiting SeImpersonate privileges via Named Pipe impersonation, supporting multiple execution methods…

Windows privilege escalation tool exploiting SeImpersonate privileges via Named Pipe impersonation, supporting multiple execution methods…


CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

Offensive MSSQL toolkit written in Python, based off SQLRecon

mssql 终端连接工具|命令执行


PoC CVE

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Self-developed tools for Lateral Movement/Code Execution
