
RunPE
C# Reflective loader for unmanaged binaries.

C# Reflective loader for unmanaged binaries.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Manipulating and Abusing Windows Access Tokens.

Local privilege escalation via PetitPotam (Abusing impersonate privileges).


Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

A C# implementation of dumping credentials from Windows Credential Manager

Wi-Fi Geolocation Spoofing with ESP8266 / ESP32

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

CVE 2020-10135 a.k.a BIAS (Bluetooth Impersonation Attack)

CVE-2019-13498

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites