
CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak

Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Hunting for passwords with deep learning

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

Source Code Management Attack Toolkit

A tool to query for the existence of pre-windows 2000 computer objects.

CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC

A script that helps you understand why your E-Mail ended up in Spam

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

A tool for pointesters to find candies in SharePoint

Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

A projectdiscovery driven attack surface monitoring bot powered by axiom

A Python based ingestor for BloodHound

Microsoft Signed PowerShell scripts

Various Cobalt Strike BOFs

A care package of useful bofs for red team engagments