
CVE-2025-50505
Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Trying to tame the three-headed dog.


VMware Aria Operations for Logs CVE-2023-34051

Using IPv6 to Bypass Security

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

CVE-2025-33073

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication to compromise Active Directory domain controllers and escalate…

Tool for Active Directory Certificate Services enumeration and abuse

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Penetration testing framework with AI-driven decision engine

Passive network security sniffer that analyzes 28 protocols (ARP, STP, OSPF, VLAN, SCADA) to detect vulnerabilities in network equipment without…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Local Privilege Escalation in HP Support Assistant