
Fenrir
PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)


Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID


PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Serverless AITM Simulation Framework for Entra ID and M365

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Here is a simple but effective exploit for CVE-2025-29927.

Proof-of-concept exploit for CVE-2024-56433, demonstrating privilege escalation via shadow-utils subordinate ID collision to access other users' data.

Exploit for CVE-2019-14287, a sudo vulnerability allowing privilege escalation to root via crafted user ID specification. Provides a proof-of-concept…

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

COFF file (BOF) for managing Kerberos tickets.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…