
icebreaker
Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…


Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Tool to discover external and internal network attack surface

Technical Reference to multiple relay techniques

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

CVE-2025-29927 Proof of Concept

Microsoft Network Service Fingerprinting Tool


Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…