
SharpHound2
The Old BloodHound C# Ingestor (Deprecated)

The Old BloodHound C# Ingestor (Deprecated)

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…

Validates and confirms the presence of CVE-2026-58231 in authorized environments via a lightweight Python script for vulnerability research,…

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO


A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A swiss army knife for pentesting networks

Converting your AR150 to a Wifi Pineapple NANO

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

Verify Next.js CVE-2025-29927 on Netlify not vulnerable

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

JF⚡can - Super fast port scanning & service discovery using Masscan and Nmap. Scan large networks with Masscan and use Nmap's scripting abilities to…