
osTicketFileReadIntoRCE
Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

Suite for reverse shell handling geared toward working within the native shell

MAL-015: Isolation Escape 2 in Ansible Tower

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

Tool for Active Directory Certificate Services enumeration and abuse

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Windows Remote Administration Tool via Telegram

Post-exploitation tool for identifying, profiling, and attacking Microsoft SCCM assets within Active Directory domains, streamlining credential…

Malicious WMI Events using PowerShell

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

C# Utilities for Windows Notification Facility

A small Aggressor script to help Red Teams identify foreign processes on a host machine

A network data locater using credentials obtained during penetration tests

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Exploiting HID VertX and EDGE access control systems

A chromium extension exploitation toolkit