
VMkatz
Extract Windows credentials directly from VM memory snapshots and virtual disks

Extract Windows credentials directly from VM memory snapshots and virtual disks

Informe técnico de una vulnerabilidad ya corregida en Instagram Notes que exponía el audio original de vídeos mediante URLs directas.


High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…


A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Public disclosure and patch for CVE-2025-63914: Zip bomb vulnerability in Cinnamon/kotaemon.

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC


CVE-2020-27688

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

InfoHound is an OSINT to extract a large amount of data given a web domain name.

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.