


Authentication, authorization, traceability and auditability for SSH accesses.

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

Azure JWT Token Manipulation Toolset

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass


Ivanti Neurons for ITSM (On Premise) exploits

PoC and exploit for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager management interfaces, enabling…

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Exploit chain for unauthenticated RCE on Microsoft SharePoint, combining a JWT authentication bypass with unsafe .NET type instantiation to achieve…

A PoC exploit for CVE-2018-9995 - DVR Authentication Bypass

CVE-2026-63030 / wp2shell

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…