
Exchange2domain
CVE-2018-8581

CVE-2018-8581

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Open source C2 server created for stealth red team operations

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

Step-by-step guide to exploiting MS17-010 EternalBlue vulnerability on Windows Server 2008 R2, including reconnaissance, exploitation,…

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

A compact guide to network pivoting for penetration testings / CTF challenges.

Remotely Enumerate sessions using undocumented Windows Station APIs

LDAP Swiss Army Knife

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2…