
CVE-2026-41089
Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

DDoS script meant to flood websites.

Collection of penetration testing tools

Easy 802.1Q VLAN Hopping

Cisco Adaptive Security Appliance and FTD Unauthorized Remote File Reading


Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Add POST body excerpt to Bro's HTTP log

Corelight@Home script

Softsensor Docker prototype

Top DNS Measurement for Bro

Detection script for telnetd CVE-2026-32746 that probes remote hosts to identify vulnerable LINEMODE support via TCP connection, generating detection…

bbs is a router for SOCKS and HTTP proxies. It exposes a SOCKS5 (or HTTP CONNECT) service and forwards incoming requests to proxies or chains of…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

