
Shadow-Vault
Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

The SSH Multiplex Backdoor Tool

Just poc for CVE 2024-54085

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

A little tool to play with Windows security

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

CVE-2023-23192

Trying to tame the three-headed dog.

Remote operations commands implemented using Beacon Object Files