
BloodHound
Six Degrees of Domain Admin

Six Degrees of Domain Admin

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

CredsHunter - Credential Hunting scripts for Windows and Linux OS

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

Windows protocol library, including SMB and RPC implementations, among others.

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

The SpecterOps project management and reporting engine

CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…
