
Pentest-tools
Intranet penetration tools

Intranet penetration tools

Golang malware development library

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

exploitdb // The official Exploit-Database repository


Activation Context Hijacking Evasion Tool

Remote DLL Injection with Timer-based Shellcode Execution

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

abusing windows toast notifications for fun and user manipulation

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

A care package of useful bofs for red team engagments

windows api bug

Tools for attacking Computer Use Agents