
awind-research
This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).

Password attacks and MFA validation against various endpoints in Azure and Office 365

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Python and Powershell internal penetration testing framework

A tool to perform Kerberos pre-auth bruteforcing

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

SharpSploit is a .NET post-exploitation library written in C#

Software to identify the different types of hashes -

A Password Spraying tool for Active Directory Credentials by Jacob Wilkin(Greenwolf)

Automated Linux evil maid attack