
otp-bot
Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Create fake certs for binaries using windows binaries and the power of bat files

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

Advanced Network Interface Management and Monitoring

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

A framework for constructing self-spreading binaries

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

VMware Aria Operations for Logs CVE-2023-34051

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

A C# implementation of dumping credentials from Windows Credential Manager

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Network Pivoting Toolkit

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Proof-of-concept exploit for Windows local privilege escalation (CVE-2023-21746) abusing NTLM local authentication to gain SYSTEM privileges via SMB…