
PHP-CGI-INTERNAL-RCE
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

CVE-2025-29927: Next.js Middleware Exploit


Enterprise-grade honeypot system for detecting internal network breaches, external threats, and producing threat intelligence with 90+ service…

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Automation for internal Windows Penetrationtest / AD-Security

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

automato should help with automating some of the user-focused enumeration tasks during an internal penetration test.

Security awareness training tool for authorized phishing simulations and internal IT audits