

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Orbis is an full spectrum automated external attack surface intelligent toolkit.

SSH spreading made easy for red teams in a hurry

Python implementation of OpenPsPipeJack

An extensible toolkit providing penetration testers an easy-to-use platform to deploy Access Points during penetration testing and red team…


Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

The recursive internet scanner for hackers. 🧡