
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

🛠️ Explore custom C2 TTPs with Aether-C2-Framework, focusing on lightweight Rust implants and stealthy transport stacks to reduce forensic…

Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.

Python implementation of OpenPsPipeJack

Local privilege escalation proof-of-concept for CVE-2026-64531 abusing OVS kernel datapath to corrupt credentials and gain root via sudoers injection.


C# Utilities for Windows Notification Facility

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

Retrieve AD accounts description and search for password in it


A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.