
PowerTools
Collection of offensive PowerShell projects for reconnaissance, privilege escalation, and post-exploitation during penetration testing engagements.

Collection of offensive PowerShell projects for reconnaissance, privilege escalation, and post-exploitation during penetration testing engagements.

Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields →…

Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000…

Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847

Real Spaces - WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator

Shell script to detect and exploit CVE-2019-14287 sudo privilege bypass vulnerability, with standalone or scanner-integrated enumeration mode.

Linux kernel version checker that suggests known local privilege escalation exploits based on the system's kernel release.

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin…

Weaponized web shell

Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments

Detection script for CVE-2021-42278 and CVE-2021-42287

AI-Powered Active Directory Attack Path Analysis with BloodHound - By Ayi NEDJIMI https://ayinedjimi-consultants.fr

Identify privilege escalation paths within and across different clouds

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…