
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Modern tactical exploitation toolkit.

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Suite de herramientas que sacan partido del CVE-2017-9097 (+RCE)

This tool uses a combination of dictionary-based wordlists (brute-force) and DNS resolution checks to verify the existence of subdomains.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…


Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

Brute-force scraper for HackerOne disclosed reports via their public API, collecting report IDs, links, titles, and states for security research and…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Making Favicon.ico based Recon Great again !

CVE-2023-23397 C# PoC

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

Brute Hikvision CAMS with CVE-2021-36260 Exploit
