
ipfire-2-25-auth-rce
ipfire 2.25 authenticated remote code execution

ipfire 2.25 authenticated remote code execution

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…


This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT…

Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user

Post-exploitation tool for hiding processes from monitoring applications

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…