
Malicious-MCP
A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

CVE 2020-10135 a.k.a BIAS (Bluetooth Impersonation Attack)

Repository for CVE-2023-4279 vulnerability.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Phishing with a fake reCAPTCHA

Stop Windows Defender programmatically

A User Impersonation tool - via Token or Shellcode injection

transform your payload.exe into one fake word doc (.ppt)

Some scripts to abuse kerberos using Powershell

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

A windows token impersonation tool