
CVE-2022-37706
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp…

Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp…

A script to automate privilege escalation with CVE-2023-22809 vulnerability

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

Grab ssh keys from ssh-agent

Powershell Empire Persistence finder

Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

A proof-of-concept for CVE-2026-39987

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

Proof-of-concept exploit for CVE-2022-1257 that extracts and decrypts stored credentials from the McAfee Agent database (ma.db) using PowerShell.

Arducky - Arduino Ducky Script Interpreter

A small Aggressor script to help Red Teams identify foreign processes on a host machine

A script to test an RDP host for sticky keys and utilman backdoor.

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)