
SharpStartWebclient
Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

A C# implementation of dumping credentials from Windows Credential Manager

Dumps TeamViewer ID,Password and account settings from a running TeamViewer instance by enumerating child windows.

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Dump Kerberos tickets from the KCM database of SSSD

Extract registry and NTDS secrets from local or remote disk images

VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

method 59 from UACME in a standalone .C

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase"…

Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and…

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…