
NetExec
Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Kernel mode WinDbg extension and PoCs for token privilege investigation.

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Downgrade attack for CVE-2025-48804

Adversary Emulation Framework

Collects Active Directory object metadata, group memberships, sessions, ACLs, and trusts to feed BloodHound attack-path mapping for security…

Powerview on steroids

Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Dump Kerberos tickets from the KCM database of SSSD

GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Tool to enumerate privileged Scheduled Tasks on Remote Systems

CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)