
pwneye
Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥

Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

Plug-and-play hashcat wrapper that cracks password hashes using preconfigured dictionary, rule-based, combinator, and mask attacks, supporting dozens…

Hashcat reference for OSCP/penetration testing: hash identification, cracking syntax for Linux, Windows, archives, databases, Kerberos tickets, and…

Offensive 802.11 auditing tool that automates WPA/WPA2 handshake and PMKID capture using deauthentication, rogue-client, and channel-switch attacks,…

Web vulnerability scanner written in Python3

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Wifite but USB-only & cross-platform.

Hunting for passwords with deep learning

Collection of VBA macro published in our twitter / blog