
sshamble
Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.


A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

User Enumeration vulnerability in Kaiten (workflow management system)

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

SharpSploit is a .NET post-exploitation library written in C#

Tools for Pentesting

Relational database brute force and post exploitation tool for MySQL and MSSQL

VPN Overall Reconnaissance, Testing, Enumeration and eXploitation Toolkit