
Seatbelt
C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

Graph-based tool for mapping and analyzing identity and privilege relationships across Active Directory, Azure, and other identity platforms to…

A lightweight, portable, and modular tool for Linux enumeration and privilege escalation.

Tool to enumerate privileged Scheduled Tasks on Remote Systems

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

Multi-threaded exploit for CVE-2026-11961 in WordPress User Registration; detects vulnerable versions and creates admin accounts, with batch…

Windows offline filesystem hacking tool for Linux

Active Directory LDAP query tool with NTLM authentication, pagination, and pre-built searches for user/group/computer enumeration, Kerberoasting,…

Interactive post-exploitation tool for Linux privilege escalation, enumeration, file exfiltration, and credential harvesting via reverse shell.

Windows vulnerability scanner that detects missing security patches and identifies known exploits and Metasploit modules for privilege escalation.

Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities

Modular penetration testing tool for Microsoft SQL Server that automates credential discovery, privilege escalation, command execution, and data…

WMI-based Windows remote execution tool for stealthy lateral movement, featuring AMSI bypass, file transfer, RID hijacking, firewall abuse, and event…

Windows tool for extracting Kerberos tickets from the LSA cache, supporting SYSTEM impersonation, session discovery, and targeted ticket dumping for…

Extensible host triage tool for red teams, dynamically loading OpSec-aware checks to gather user, domain, privilege, and credential information from…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

Exploit tool for CVE-2026-8181 targeting Burst Statistics WordPress plugin. Automates authentication bypass, user enumeration, admin account…