
FaceBrute
Facebook brute forcer script

Facebook brute forcer script

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Open YARA scan- and search engine

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting…

Brute Hikvision CAMS with CVE-2021-36260 Exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

Possible Account Takeover | Brute Force Ability

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Medium-interaction SSH honeypot that logs brute force attacks and full attacker shell interactions, with customization options to reduce…