
CVE-2026-41089
Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload…

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

CVE-2024-6387 with auto ip scanner and auto expliot

CVE-2024-4577 Mass Scanner & Exploit Tool

Cisco Catalyst SD-WAN Peering Authentication Bypass

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

Dumain Bruteforcer - a fast and flexible domain bruteforcer

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Six Degrees of Domain Admin

Six Degrees of Domain Admin

C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Python script using Impacket to test for CVE-2020-1472 (Zerologon) vulnerability via Netlogon authentication bypass on Windows domain controllers.

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names