
BrokenPipe
Steam Client Service Local Privilege Escalation Vulnerability

Steam Client Service Local Privilege Escalation Vulnerability

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

PoC Exploit for the NTLM reflection SMB flaw.

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

CVE-2021-42287/CVE-2021-42278 exploits in powershell

C# Reflective loader for unmanaged binaries.

Kerberos relaying and unconstrained delegation abuse toolkit

Python implementation of OpenPsPipeJack

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Manipulating and Abusing Windows Access Tokens.

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

A basic emulation of an "RPC Backdoor"

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.