
DeadMatter
Offset Independent Credential Extraction Tool

Offset Independent Credential Extraction Tool

Provable check for CVE-2022-40769: does an EOA's private key lie in the Profanity-reachable key space?

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

All-in-one Image Steganography Toolkit for CTFs & Forensics

Retrieve AD accounts description and search for password in it

Wordlist to crack .zip-file password

A list of awesome penetration testing tools and resources.

Very Slow HMAC Key Bruteforcer

publiccms_decrypt

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Check rclone config files for insecure passwords

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Generate mutations over a wordlist

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

Python script that will extract all saved passwords from your google chrome database on windows only

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…