
CVE-2023-48795
Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

CVE-2026-66804 Windows Cross Device virtual camera EoP - private internal research repository

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Course repository for PowerShell for Pentesters Course

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

Proof-of-concept for CVE-2026-11106 exploiting unrestricted DNS AXFR zone transfers to enumerate domain records, expose internal hosts, and leak…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Dockerized reproduction of CVE-2026-59774 for Gitea; demonstrates path traversal in go-org markup include to read arbitrary files and escalate to RCE…

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

An ADCS honeypot to catch attackers in your internal network.

CVE-2025-29927: Next.js Middleware Exploit



Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…