
tfo-connect-bypass
Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

A collaborative, multi-platform, red teaming framework

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Activation Context Hijacking Evasion Tool

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

A modern 32/64-bit position independent implant template

A easy sudo poc by cryingn.

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Mimikatz implementation in pure Python

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

Six Degrees of Domain Admin

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

Azure Post Exploitation Framework

Automation for internal Windows Penetrationtest / AD-Security

Code execution/injection technique using DLL PEB module structure manipulation