
CVE-2026-55040
Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…


Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Some scripts to abuse kerberos using Powershell

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

Rusty Impersonate

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Simple shell script to "clone" X.509 certificates

Ask a TGS on behalf of another user without password

Leverage WindowsApp createdump tool to obtain an lsass dump

Phishing with a fake reCAPTCHA

RunasCs - Csharp and open version of windows builtin runas.exe

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.