
PyPsPipeJack
Python implementation of OpenPsPipeJack

Python implementation of OpenPsPipeJack

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Some scripts to abuse kerberos using Powershell

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

Windows Session Hijacking via COM

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Rusty Impersonate

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

Leverage WindowsApp createdump tool to obtain an lsass dump

RunasCs - Csharp and open version of windows builtin runas.exe

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…