
RedTeamScripts
Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

A collection of all the data i could extract from 1 billion leaked credentials from internet.

Offensive Lua.

This repository presents a proof-of-concept of CVE-2023-7028

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

Grafana Bruteforce tool

A python3 multithreaded SSH dictionary attack tool

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

trojan CVE-2024-28085 CVE 28085

Objective-C library and console to interact with Heimdal APIs for macOS Kerberos

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…


User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset