
sshuttle
Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

SMB vulnerability scanner that detects CVE-2019-1040 by sending invalid NTLM authentication packets, enabling MIC Remove relay attacks for domain…

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

Curated RDP Wireshark captures illustrating Kerberos, NTLM, smartcard, NLA, Restricted Admin, Credential Guard, RD Gateway, and clipboard redirection…

Lightweight Python utility to enable telnet on Netgear routers (R7000, R7500) using LAN MAC and admin credentials. Useful for penetration testing,…

Self-hosted WireGuard mesh VPN with browser-based admin portal, Winbox proxy, WebSSH, and WebProxy for managing remote devices and IoT infrastructure…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

Web-based admin UI for AAA/TACACS+ services, providing centralized management of authentication, authorization, accounting rules, and system…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

Hackable HTTP proxy for resiliency testing and simulated network conditions
