
NPE-CS-V-CVE-2021-1675
Exploit code for CVE-2021-1675, a Windows Print Spooler remote code execution vulnerability, demonstrating the attack and providing a…

Exploit code for CVE-2021-1675, a Windows Print Spooler remote code execution vulnerability, demonstrating the attack and providing a…

Vulnerable Samba 3.0.24 environment for reproducing CVE-2007-2447 command execution, intended for exploit testing and security research.

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Multiplayer pivoting solution

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

Exploit for CVE-2021-36934

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Trying to tame the three-headed dog.

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#