
CVE-1999-0524-POC
Multi-threaded ICMP timestamp scanner that detects hosts vulnerable to CVE-1999-0524 by sending Type 13 requests and analyzing Type 14 replies,…

Multi-threaded ICMP timestamp scanner that detects hosts vulnerable to CVE-1999-0524 by sending Type 13 requests and analyzing Type 14 replies,…

A utility for extracting system and application metrics from unprotected Prometheus Node Exporter HTTP endpoints, used to identify misconfigurations…

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash

Autonomous, modular open-hardware system for network reconnaissance, man-in-the-middle data collection, and automated exploitation with remote C2…

System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

Toolset for extracting credentials from Microsoft ConfigMgr/SCCM Operating System Deployment via PXE boot attacks, including password cracking,…

A personal RAG system for offensive security knowledge

Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.

Windows tool for extracting Kerberos tickets from the LSA cache, supporting SYSTEM impersonation, session discovery, and targeted ticket dumping for…

Recursive DNS Subdomain Enumerator with dead-end avoidance system (BETA)

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

HTA-based post-exploitation shell for breakout assessments. Provides file explorer, system reconnaissance, AD enumeration, and file transfer…

A BOF to enumerate system process, their protection levels, and more.