
Corporate_Masks
8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin…

Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access.

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Powerview on steroids

C# version of NTLMRawUnHide

Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

This repository presents a proof-of-concept of CVE-2023-7028

Leak of any user's NetNTLM hash. Fixed in KB5040434

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

tool for generating wordlists or extending an existing one using mutations.

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…