
RTI-Toolkit
PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

conduct lateral movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine

SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environments.

Scripts to clone CA certificates for use in HTTPS client attacks.

Impersonate Logged In Accounts & Execute Commands

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

C&C Botnet written in Python with fabric

Python implementation of OpenPsPipeJack

DNSint - A comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering and security analysis.

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

CVE-2021-33766-poc


CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

PoC CVE-2023-51764

Test cases for broken MIME and tools to generate and process these


Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component