
Wifi-Dumper
This is an open source tool to dump the wifi profiles and cleartext passwords of the connected access points on the Windows machine. This tool will…

This is an open source tool to dump the wifi profiles and cleartext passwords of the connected access points on the Windows machine. This tool will…

A small Aggressor script to help Red Teams identify foreign processes on a host machine

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

Tool to discover external and internal network attack surface

An ADCS honeypot to catch attackers in your internal network.

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Python and Powershell internal penetration testing framework

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

DejaVU - Open Source Deception Framework

CVE-2025-29927: Next.js Middleware Bypass Vulnerability

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment