
cve-2026-59827-metabase-cyber-range
Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Tools for attacking Computer Use Agents

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

[CVPR 2025-ADVML] Official Repository for `Attacking Attention of Foundation Models Effectively Disrupts Downstream Tasks`

JMX enumeration and attacking tool.

Toolkit for attacking MS Kerberos implementations: extract SPN accounts, request and export tickets, crack service passwords, rewrite tickets for…

An Open-Source Package for Textual Adversarial Attack.

.NET Project for Attacking vCenter

wp-file-manager RCE

Shell Script For Attacking Wireless Connections Using Built-In Kali Tools. Supports All Securities (WEP, WPS, WPA, WPA2)

wpscvn is a tool for pentesters, website owner to test if their websites had some vulnerable plugins or themes

SMB MiTM tool with a focus on attacking clients through file content swapping, lnk swapping, as well as compromising any data passed over the wire in…

[L]ocal [A]uto [R]oot [E]xploiter is a simple bash script that helps you deploy local root exploits from your attacking machine when your victim…

The great RSA Attacking Toolkit compiled for Windows