
Tangled
Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Exploitation of CVE-2025-29969

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

BOF POC of the DSCourier project / invoking WinGet via COM

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

包括能执行的命令探测和一键getshell(需要服务器部署服务)

CVE-2022-30190 | MS-MSDT Follina One Click

Exploit for SaltStack CVEs (CVE-2020-11651/11652) enabling remote command execution on master/minions, file read/upload, and reverse shell.

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Vulnerable Samba 3.0.24 environment for reproducing CVE-2007-2447 command execution, intended for exploit testing and security research.

Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time…

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)