
CVE-2024-415770-ssrf-rce
Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

psexecsvc - a python implementation of PSExec's native service implementation

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

Grab ssh keys from ssh-agent

A JBoss script for obtaining remote shell access

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

Powershell Empire Persistence finder

A small Aggressor script to help Red Teams identify foreign processes on a host machine

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

A script to test an RDP host for sticky keys and utilman backdoor.

Arducky - Arduino Ducky Script Interpreter

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

A proof-of-concept for CVE-2026-39987