
wsuks
Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Oracle OID LDAP Server Privileges Management Exploit

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

PoC Exploit for the NTLM reflection SMB flaw.

Zeek package to detect Zerologon

PoC materials to exploit the CVE-2021-1480 on Cico SD-WAN.

A delicious, but malicious SSL-VPN server 🌮

Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Windows x64 Ring 0 rootkit enabling DKOM process hiding, privilege elevation, driver swapping, and anti-malware evasion by redirecting file…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Generate Payloads and Control Remote Machines. [Discontinued]

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths