
BadSamba
This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Used to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the…

Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through…

Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845

Shortest Path Bridging (SPB-Mac) vulnerability testing scripts. Used in a network pentest to enumerate a new vuln (CVE-2016-2783) in Avaya VOSS…

Audits Active Directory SMB shares to inventory, analyze, and report excessive privileges. Discovers accessible systems, enumerates share ACLs,…

A utility to safely generate malicious network traffic patterns and evaluate controls.

Multi-protocol data exfiltration testing tool that simulates real-world egress scenarios over FTP, HTTP, HTTPS, DNS, ICMP, SMB, SMTP, and SFTP to…

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Scripts to detect Fast-Flux and DGA using DNS query responses

Verification tools for CVE-2016-1287

mud-visualizer is a tool to visualize MUD files