
PyPsPipeJack
Python implementation of OpenPsPipeJack

Python implementation of OpenPsPipeJack

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

Windows Session Hijacking via COM

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Rusty Impersonate

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command

RunasCs - Csharp and open version of windows builtin runas.exe

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

A windows token impersonation tool