
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

Course repository for PowerShell for Pentesters Course

A compact guide to network pivoting for penetration testings / CTF challenges.

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

List of Awesome CobaltStrike Resources

Asynchronous RDP client for Python (headless)

Red Teaming & Pentesting checklists for various engagements

A windows token impersonation tool

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Attempt at Obfuscated version of SharpCollection

Rusty Impersonate

OSWE, OSEP, OSED, OSEE

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.