
SockTail
Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Arbitrary file read exploit for the Windows UPnP Device Host service.

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

CVE-2026-13768 advisory detailing critical Azure IoT Hub iothubowner credential abuse enabling fleet-wide device enumeration, remote code execution…

Android remote access trojan (RAT) with remote webcam, microphone, file management, call/SMS control, and device controller capabilities for research…

Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

Proof-of-concept exploit for CVE-2026-0828, a BYOVD vulnerability in Safetica ProcessMonitorDriver.sys allowing unprivileged termination of…

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631