
MSSQLand
In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Simple shell script to "clone" X.509 certificates

Burp Suite extension for spoofing IP addresses in HTTP requests, enabling testing of server-side IP restrictions and bypassing IP-based access…

Android Faker a Simple Xposed Module Which Spoof Your Device IDs Values. Supporting Android 8.1+

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

Spoof file icons and extensions in Windows

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

A C# utility for interacting with SCOM


CVE-2019-13498

Repository for CVE-2023-4631 vulnerability.

Herramienta ideal para el despliegue automatizado de un Rogue AP con capacidad de selección de plantilla + 2FA. No requiere de conexión cableada.

Rubber Ducky compatible clone based on CJMCU BadUSB HW.