
impacket
Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates…

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…


☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Dominate Active Directory with PowerShell.

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

专为红队行动设计的CSRF登录暴力破解工具,具备动态CSRF Token刷新、多线程并发和会话恢复功能,支持高并发操作和智能重试机制。

Infection Monkey - An open-source adversary emulation platform

trojan CVE-2024-28085 CVE 28085