
TokenTactics
Azure JWT Token Manipulation Toolset

Azure JWT Token Manipulation Toolset

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

Alibab Nacos Unauthorized Login

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…


C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Authentication, authorization, traceability and auditability for SSH accesses.

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

PowerShell MachineAccountQuota and DNS exploit tools

A tool to scan Kubernetes cluster for risky permissions

POC tool for ResetNightmare (CVE-2026-27912)

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

Exploit for CVE-2020-3952 in vCenter 6.7