
cve-2026-9082-drupal-postgresql-rce
Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Proof-of-concept exploit for CVE-2022-1257 that extracts and decrypts stored credentials from the McAfee Agent database (ma.db) using PowerShell.

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

Dump Kerberos tickets from the KCM database of SSSD

POCs to demonstrate CVE-2026-42167 in ProFTPD

Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.

D-RAT [VB.NET]+[MySQL]+[PHP]

Database authenticated code execution

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Offensive MSSQL toolkit written in Python, based off SQLRecon

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting


Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…