
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Oracle OID LDAP Server Privileges Management Exploit

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

AAD related enumeration in Nim

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.


.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

A new open-source tool to quickly audit SAP permissions.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…


This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

CVE-2025-41115

CVE-2025-59501 POC code

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…