

Extract registry and NTDS secrets from local or remote disk images

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…


gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

tool to extract passwords from TeamViewer memory using Frida

Post-Exploitation EVTX Analyzer for BloodHound Mapping

WinRAR 0day CVE-2025-8088 PoC RAR Archive

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Extract Windows credentials directly from VM memory snapshots and virtual disks

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…