
Dark-Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

DHCP exhaustion script written in python using scapy network library

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

CVE-2025-54322 - XSpeeder SXZOS Pre-Auth RCE 0day Finder Quick

CVE-2025-53690 POC

XSS exploit for CVE-2025-8550 in atjiu pybbs ≤6.0.0

Mythic C2 agent targeting Linux and Windows hosts written in Rust

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks


The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

There are many cheat sheets out there, but this is mine.

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Exploit for CVE-2024-3273, supports single and multiple hosts