
kube-reaper
Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

A BOF to determine Windows Defender exclusions.

Windows Local Privilege Escalation Cookbook

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

Privilege Escalation Enumeration Script for Windows

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Post exploitation tool for configuration management servers.

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…