
stunner
Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

Technical Reference to multiple relay techniques


DLL-injectable internal game cheat for Plutonium BO2 zombies

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

The detection of internal security controls at a company

Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Automation for internal Windows Penetrationtest / AD-Security

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

DejaVU - Open Source Deception Framework

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

CVE-2025-29927: Next.js Middleware Bypass Vulnerability

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

An ADCS honeypot to catch attackers in your internal network.