
captaincredz
CaptainCredz is a modular and discreet password-spraying tool.

CaptainCredz is a modular and discreet password-spraying tool.

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…


A credential extraction BOF for Veeam Backup and Replication and Veeam One

Complete credential attack suite for authorized security testing — SSH, FTP, Web Login, Bruteforce, Dictionary attacks

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

Unauthenticated Privilege Escalation to Administrator via Role Form Field

cve-2016-16113

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Smart keylogging capability to steal SSH Credentials including password & Private Key

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Extract registry and NTDS secrets from local or remote disk images