
Vulnerability-Disclosures
Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Automation for internal Windows Penetrationtest / AD-Security

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

DLL-injectable internal game cheat for Plutonium BO2 zombies

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

The detection of internal security controls at a company

Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.

A tool to make socks connections through HTTP agents

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

Explore the network using VPNPivot tool

D(COM) V(ulnerability) S(canner) AKA Devious swiss army knife - Lateral movement using DCOM Objects

Technical Reference to multiple relay techniques

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53