
MalSCCM
Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

Self-healing RAT utilizing libp2p

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

Exploit for CVE-2024-3273, supports single and multiple hosts

Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

CVE-2025-53690 POC

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

XSS exploit for CVE-2025-8550 in atjiu pybbs ≤6.0.0


CVE-2025-54322 - XSpeeder SXZOS Pre-Auth RCE 0day Finder Quick

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…