
unshackle
Open-source tool to bypass windows and linux passwords from bootable usb

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

POC tool for ResetNightmare (CVE-2026-27912)

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Exploit tool for CVE-2023-2437 targeting UserPro <= 5.1.1 authentication bypass, allowing attackers to gain admin access and create new…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

Brute Force Wordpress Blogs.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Writeup of CVE-2020-15906

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

AuthBypass & Auto Backdooring Devices

Exploit for CVE-2025-47227 - ScriptCase Password Reset (Pre-Auth)