
vcenter_saml_login
A tool to extract the IdP cert from vCenter backups and log in as Administrator

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Automating situational awareness for cloud penetration tests.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

getshell test

Modified version of CVE-2019-5736-PoC by Frichetten

POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation

Peirates - Kubernetes Penetration Testing tool

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

a guard that blocks catastrophic agent actions

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

📦 Make security testing of K8s, Docker, and Containerd easier.

A collection of scripts for assessing Microsoft Azure security