
Ciphey
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

Decrypt GlobalProtect configuration and cookie files.

SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers

Abuses Windows Hello from a privileged context to enumerate protectors, decrypt keys, extract PRT/TGT tokens, proxy WebAuthn requests, and dump…

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…

Python script to decrypt data encrypted by the Java PasswordCipher class, exploiting CVE-2024-5764's static encryption key in Sonatype Nexus…

Decrypt FortiGate configuration files and encrypted strings to detect default encryption keys, enabling rapid assessment of CVE-2019-6693…

Proof-of-concept exploit for CVE-2026-26012, a broken access control in Vaultwarden that allows any organization member to enumerate and decrypt all…

Weak encryption in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject wireless…

Exploit for CVE-2024-43044 enabling arbitrary file read from Jenkins controller to extract and decrypt credentials.xml using secret keys.

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

An experimental script PoC for Kr00k vulnerability (CVE-2019-15126)