
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

📜 Scrape targeted wordlists for password cracking using CSS selectors

tool for generating wordlists or extending an existing one using mutations.

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

A POSIX-compliant, fully automated WPA PSK PMKID and handshake capture script aimed at penetration testing

Wordlists handcrafted (and automated) with ♥

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

Generates targeted password wordlists by combining personal info, applying case/leet transforms, and scraping artist lyrics for enhanced cracking…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Working Python exploit for CVE-2019-9053 with optional password cracking via wordlist. Targets web applications via HTTP URI for automated…

A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Automated OSINT framework for ethical hacking audits. Collects employee emails, password hashes, subdomains, and IPs via BreachDirectory and…