
sshuttle
Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

Self-hosted WireGuard mesh VPN with browser-based admin portal, Winbox proxy, WebSSH, and WebProxy for managing remote devices and IoT infrastructure…


Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

Curated RDP Wireshark captures illustrating Kerberos, NTLM, smartcard, NLA, Restricted Admin, Credential Guard, RD Gateway, and clipboard redirection…

Web-based admin UI for AAA/TACACS+ services, providing centralized management of authentication, authorization, accounting rules, and system…

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

Lightweight Python utility to enable telnet on Netgear routers (R7000, R7500) using LAN MAC and admin credentials. Useful for penetration testing,…

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

Hackable HTTP proxy for resiliency testing and simulated network conditions

SMB vulnerability scanner that detects CVE-2019-1040 by sending invalid NTLM authentication packets, enabling MIC Remove relay attacks for domain…