
CVE-2025-33073
PoC Exploit for the NTLM reflection SMB flaw.

PoC Exploit for the NTLM reflection SMB flaw.

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Educational proof-of-concept for PrintNightmare (CVE-2021-1675/34527) with simulated non-functional payload, attack flow analysis, MITRE mapping,…

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Kerberos relaying and unconstrained delegation abuse toolkit

Collects Active Directory object metadata, group memberships, sessions, ACLs, and trusts to feed BloodHound attack-path mapping for security…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

Python implementation of OpenPsPipeJack

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

Manipulating and Abusing Windows Access Tokens.

Course repository for PowerShell for Pentesters Course

A compact guide to network pivoting for penetration testings / CTF challenges.

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

RunasCs - Csharp and open version of windows builtin runas.exe

List of Awesome CobaltStrike Resources