
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

A credential extraction BOF for Veeam Backup and Replication and Veeam One

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

Automated exploit tool combining CVE-2019-17240 authentication bypass and CVE-2019-16113 arbitrary file upload to achieve remote code execution on…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

Dumps LSASS memory by abusing Microsoft-signed WindowsApp createdump.exe, using a custom dbgcore.dll hook and winlogon impersonation for credential…

Go-based exploit for CVE-2023-6875 that intercepts admin password reset emails, logs in, and uploads a web shell to the target server.

Rust-based Windows LSASS credential dumper using MiniDumpWriteDump with custom callbacks to bypass EDR; includes GUI, CMD, and decryption modes for…

Proof-of-concept exploit for CVE-2023-23397 that crafts malicious Outlook emails to leak Net-NTLMv2 hashes via UNC path in…

C# tool for Kerberos protocol manipulation, enabling ticket requests, delegation (S4U), kerberoasting, AS-REP roasting, and golden/silver ticket…

Collection of VBA macro published in our twitter / blog

Python exploit for CVE-2019-19609 targeting Strapi CMS 3.0.0-beta.17.4. Resets admin password and executes remote commands via JWT token manipulation.

WordPress attack suite with API-based brute-force login, automated shell upload, post-exploitation modules including hash dumping, keylogger, BeEF…

Automated credential dumping tool with custom PowerShell payloads, in-memory execution, Mimikatz parsing, ticket dumping, and web-based dashboard for…

Automated Linux evil maid attack tool that backdoors initrd images to drop a meterpreter shell and exfiltrate full-disk encryption passwords upon…