
BloodHound
Six Degrees of Domain Admin

Six Degrees of Domain Admin

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF


CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.


Exploit PoC of CVE-2026-6356

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…



The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…
