
poc-2025-9074
Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Automated Kubernetes penetration testing tool for privilege escalation, service account token theft, secret collection, and cluster pivot attacks…

A container analysis and exploitation tool for pentesters and engineers.

Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

React2Shell Exploitation Tool (CVE-2025-55182)

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

DPAPI looting remotely and locally in Python

Extracts and decrypts Azure AD Connect (ADSync) credentials from hybrid identity sync servers for post-exploitation credential recovery.