
CVE-2025-4275
Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…

Windows post-exploitation reconnaissance agent that collects system info, privileges, patches, defenses, network config, credentials, and persistence…

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Attack and defend active directory using modern post exploitation adversary tradecraft activity

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

iOS/macOS/Linux Remote Administration Tool

📦 Make security testing of K8s, Docker, and Containerd easier.

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Collection of Offensive C# Tooling

An evil RAT (Remote Administration Tool) for macOS / OS X.

A tool to abuse Exchange services

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )