
pentestcode
Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Entra ID Password Protection Banned Password Lists

IPSpinner works as a local proxy that redirects requests through external services.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Tool to spray AWS Console IAM Logins

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)


A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Password spraying using AWS Lambda for IP rotation