
area51
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Steam Client Service Local Privilege Escalation Vulnerability

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

AI-driven OSINT and security research agent that builds a live knowledge graph from public data, with bundled recon tools and offensive-security…

Proof-of-concept exploit for CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration Suite via zimbra-snmp log injection,…

Docker-based lab and Python exploit for CVE-2026-18963, a Keycloak reset-credentials flow bypass enabling account takeover via email verification…

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Hunt down social media accounts by username across social networks

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Stored XSS in Nagios Log Server 2024R1.3.1

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Common library for tools implementing GPO attack vectors

Dump Kerberos tickets from the KCM database of SSSD

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…