

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Some scripts to abuse kerberos using Powershell

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

Simple shell script to "clone" X.509 certificates

Leverage WindowsApp createdump tool to obtain an lsass dump

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

Scripts to clone CA certificates for use in HTTPS client attacks.

Incriminator is an OpenSource Project with educational purposes that allows you to incriminate other devices during a cybercrime.

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…