
CVE-2018-13341
Exploit tool for CVE-2018-13341 that recovers the hidden 'crengsuperuser' password from Crestron TSW-XX60 devices using the MAC address, enabling…

Exploit tool for CVE-2018-13341 that recovers the hidden 'crengsuperuser' password from Crestron TSW-XX60 devices using the MAC address, enabling…

PowerShell-based remote administration tool (RAT) with keylogging, remote shell, and file management capabilities for covert system control.

Automated IBM/Lotus Domino server assessment tool for fingerprinting, directory enumeration, reverse brute force authentication, hash dumping, and…

CLI password mutation tool applying transformation rules (leet, reverse, case-swap) to generate password variants for security testing and…

Automated Linux evil maid attack tool that backdoors initrd images to drop a meterpreter shell and exfiltrate full-disk encryption passwords upon…

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

Android-based HTTP/S brute-force tool for credential testing with customizable wordlists, regex-based success detection, and runtime parameter…

Brute-force tool that cracks iOS restriction passcodes by extracting PBKDF2 hashes from unencrypted iTunes backups, supporting PIN guessing and…

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Shell script for Windows domain penetration testing: finds common password hashes and locates Domain Administrator accounts using pass-the-hash…

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

📜 Scrape targeted wordlists for password cracking using CSS selectors

High-speed SSH brute-force tool with CLI interface, post-attack command execution, and Telegram bot integration for automated report delivery.

Generate wordlists using pattern logic and expressions.

Highly configurable script for dictionary/spray attacks against online web applications.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Multi-service brute-force, port scanning, web fingerprinting, and one-click exploitation tool for intranet penetration testing. Supports RDP, SSH,…

Tool to decrypt OpenFire management console passwords by retrieving the encrypted password and key from the database and applying Blowfish decryption.