
CVE-2026-55040
Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

Rusty Impersonate

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

This is a SMS And Call Bomber For Linux And Termux

Ask a TGS on behalf of another user without password

RunasCs - Csharp and open version of windows builtin runas.exe

Real-time deepfake toolkit for penetration testing of identity verification and video conferencing systems. Supports face swap, image animation, and…

Create fake certs for binaries using windows binaries and the power of bat files

A C# implementation of dumping credentials from Windows Credential Manager