
Burp-Suite-Certified-Practitioner-Exam-Study
Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

A care package of useful bofs for red team engagments

Offensive pentest toolkit combining OSINT, information gathering, SMB brute force, and Metasploit-compatible Meterpreter stagers for Windows/AD…

Automated builds of obfuscated C# offensive tools for red teams, covering AD enumeration, credential access, lateral movement, and privilege…

Exploit Jenkins instances via CVE-specific PoCs: RCE through Groovy scripts and deserialization, dump builds for cleartext secrets, password…

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

Collection of Python scripts for vulnerability exploitation, credential attacks, and post-exploitation on web applications, Exchange, vCenter, and…

Collection of PowerShell-based tools for intranet penetration testing, including reconnaissance, lateral movement, privilege escalation, and…

Automated mass scanner for CVE-2026-3584, an unauthenticated RCE in WordPress Kali Forms. Executes a 4-phase pipeline: REST API enumeration, form…

Penetration testing framework with AI-driven decision engine

Proof-of-concept exploit for CVE-2026-57827: unauthenticated file upload RCE in RSFiles! Joomla component. Includes mass scanning and automated shell…

Collection of proof-of-concept exploits and payloads for CVE-2019-0708 (BlueKeep) vulnerability, targeting RDP remote code execution for penetration…

Work in Progress. RAT written in C++ using wxWidgets

CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)