
Get-NetNTLM
Powershell module to get the NetNTLMv2 hash of the current user

Powershell module to get the NetNTLMv2 hash of the current user

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

Collection of DFIR and OSINT Python scripts for parsing malicious LNK samples, extracting OLE objects from MHTML, and hashing favicons to hunt…

Generate a favicon that results in any target hash on Shodan

Markov model-based password guesser in C that enumerates candidates by probability, generating most likely passwords first for hash cracking via…

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

Offset Independent Credential Extraction Tool

Proof-of-concept decrypting Araxis Merge's DPAPI-protected server credentials (CVE-2026-92680), demonstrating insufficiently protected credential…

Python 3 exploit for CVE-2019-9053, a CMS Made Simple SQL injection vulnerability, enabling credential extraction via time-based blind SQLi and…

Advisory for CVE-2026-77771, a 2FA bypass in the miniOrange WordPress plugin via session-scoped OTP lockout, with impact analysis and remediation…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Fast and easy-to-use directory brute-forcer written in Go.

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.

Brute Ratel C4 BOF that exploits a registry symlink race condition in Windows Accessibility ATConfig to escalate privileges to SYSTEM by writing…

Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.