
nccfsas
Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

Modern tactical exploitation toolkit.

A DNS rebinding attack framework.

Notes about attacking Jenkins servers

Collection of Offensive C# Tooling

SharpSploit is a .NET post-exploitation library written in C#

Open source C2 server created for stealth red team operations

Intranet penetration tools

LSTAR - CobaltStrike 综合后渗透插件

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Python codes of my blog.

abusing windows toast notifications for fun and user manipulation

hacklib - pentesting, port scanning, and logging in anywhere with Python

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

A care package of useful bofs for red team engagments

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit