
SockTail
Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Android remote access trojan (RAT) with remote webcam, microphone, file management, call/SMS control, and device controller capabilities for research…

Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

Arbitrary file read exploit for the Windows UPnP Device Host service.

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

CVE-2026-13768 advisory detailing critical Azure IoT Hub iothubowner credential abuse enabling fleet-wide device enumeration, remote code execution…