


An OSINT tool that helps detect members of a company with leaked credentials


OSINT Tool for Finding Passwords of Compromised Email Addresses


Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…


Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info


Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

Guesses hash types, picks some sensible dictionaries and rules for hashcat

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.