
KnockOutlook
C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

[unmaintained] Post-exploitation tool

Abuses Windows Hello from a privileged context to enumerate protectors, decrypt keys, extract PRT/TGT tokens, proxy WebAuthn requests, and dump…

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

DoSinator is a powerful Denial of Service (DoS) testing tool developed in Python.

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

powershell tool for VM evasion

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Detection artifact generator for CVE-2025-52691, a pre-auth path traversal leading to unauthenticated RCE in SmarterMail. Probes vulnerable builds by…

Detection artifact generator for Ivanti EPMM pre-auth RCE chain (CVE-2025-4427 + CVE-2025-4428). Executes commands to verify vulnerability status…

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

Exploits CVE-2026-41940, a cPanel & WHM authentication bypass, to gain root WHM access and run post-exploitation commands, file reads, and account…

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

A nice tool that automates network hash capturing and has a nice GUI. Read README.md for more information and NEVER use this without explicit…

Unified Security Research Tool

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

Tool for Active Directory Certificate Services enumeration and abuse