
GPOHound
Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Correlates NTLM hashes, BloodHound data, and cracked passwords for Active Directory penetration testing. Imports NTDS.dit, syncs to Neo4j, analyzes…

Proof-of-concept exploit for CVE-2026-32488 targeting WordPress user registration via crafted POST requests to admin-ajax.php, enabling…

Powerview on steroids

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Tomcat - PUT Method

Python script to check for CVE-2023-2745 vulnerability by sending crafted HTTP requests to a target URL and analyzing responses.

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

Proof-of-concept exploit for CVE-2022-28117 enabling arbitrary file read via file:/// URI scheme in Navigate CMS, with authentication support.

X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。


Scanner CVE-2019-0708

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC