
LinPwn
Interactive post-exploitation tool for Linux privilege escalation, enumeration, file exfiltration, and credential harvesting via reverse shell.

Interactive post-exploitation tool for Linux privilege escalation, enumeration, file exfiltration, and credential harvesting via reverse shell.

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

This is a pre-authenticated RCE exploit for VMware vRealize Operations Manager

A care package of useful bofs for red team engagments

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

An interactive CLI application for interacting with authenticated Jupyter instances.

Sudo exploit

Python script to efficiently find files on UNIX like file systems with specific properties (quicker than find)

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

on Mac 10.12.2

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Pure-Nim network enumeration and remote execution toolkit for authorized security assessments. Supports SMB, LDAP, Kerberos, WinRM, database clients,…

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

Python script for privilege escalation for Python

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

cups-root-file-read.sh | CVE-2012-5519

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator