
CVE-2020-12712
Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

Plug-and-play hashcat wrapper that cracks password hashes using preconfigured dictionary, rule-based, combinator, and mask attacks, supporting dozens…

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Notes about attacking Jenkins servers

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

COFF file (BOF) for managing Kerberos tickets.

Xenotix Python Keylogger for Windows.

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Tool for checking passwords against TrueCrypt encrypted volumes and disks, and/or decrypting the data.

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Prepostseo Login Checker

Password decryption tool for the McAfee SiteList.xml file

Opens 1K+ IPs or Shodan search results and attempts to login

WPBF - a multithreaded WP brute forcer

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…