
Blackash-CVE-2025-31161
CVE-2025-31161

CVE-2025-31161

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

TP-Link Archer BE800 V1 — VPN Key Injection RCE

Six Degrees of Domain Admin

Six Degrees of Domain Admin

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

For when you want a computer to be done - without admin!

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

Permanently disable EDRs as local admin

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Netwrix Account Lockout Examiner 4.1 Domain Admin Account Credential Disclosure Vulnerability

Exploit for CVE-2022-44721 that bypasses CrowdStrike Falcon uninstall protection token check on Windows, allowing attackers with admin privileges to…

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…