Skip to content
Change the repository type filter

All

    Repositories list

    • shh

      Public
      Systemd Hardening Helper
      Rust
      GNU General Public License v3.0
      110310Updated Nov 25, 2024Nov 25, 2024
    • Exploit code for CVE-2023-42914 / pwn2own Vancouver 2023
      C
      0000Updated Nov 22, 2024Nov 22, 2024
    • Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.
      Python
      GNU General Public License v3.0
      1425400Updated Nov 21, 2024Nov 21, 2024
    • octoscan

      Public
      Octoscan is a static vulnerability scanner for GitHub action workflows.
      Go
      GNU General Public License v3.0
      1117332Updated Nov 13, 2024Nov 13, 2024
    • A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.
      Python
      MIT License
      01500Updated Nov 12, 2024Nov 12, 2024
    • GPOddity

      Public
      The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).
      Python
      2126510Updated Nov 8, 2024Nov 8, 2024
    • bbs

      Public
      bbs is a router for SOCKS and HTTP proxies. It exposes a SOCKS5 (or HTTP CONNECT) service and forwards incoming requests to proxies or chains of proxies based on the request's target. Routing can be configured with a PAC script (if built with PAC support), or through a JSON file.
      Go
      48200Updated Oct 30, 2024Oct 30, 2024
    • SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.
      Python
      1916500Updated Oct 28, 2024Oct 28, 2024
    • 📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.
      Shell
      GNU General Public License v3.0
      02300Updated Oct 28, 2024Oct 28, 2024
    • eos

      Public
      Enemies Of Symfony - Debug mode Symfony looter
      Python
      Other
      4931401Updated Oct 18, 2024Oct 18, 2024
    • A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.
      Python
      41800Updated Oct 13, 2024Oct 13, 2024
    • Rust ADB client
      Rust
      2910Updated Oct 10, 2024Oct 10, 2024
    • DepFuzzer

      Public
      Python
      MIT License
      54021Updated Oct 8, 2024Oct 8, 2024
    • Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
      Python
      127300Updated Oct 7, 2024Oct 7, 2024
    • krbrelayx

      Public
      Kerberos unconstrained delegation abuse toolkit
      Python
      MIT License
      171000Updated Oct 3, 2024Oct 3, 2024
    • garble

      Public
      Obfuscate Go builds
      Go
      BSD 3-Clause "New" or "Revised" License
      262000Updated Sep 25, 2024Sep 25, 2024
    • Python3 rewrite of AsOutsider features of AADInternals
      Python
      MIT License
      23600Updated Sep 11, 2024Sep 11, 2024
    • kcmdump

      Public
      Dump Kerberos tickets from the KCM database of SSSD
      Python
      54900Updated Sep 8, 2024Sep 8, 2024
    • Proof-of-concept Velociraptor artifacts pack to showcase a remote Veeam forensics pipeline.
      GNU Affero General Public License v3.0
      0000Updated Aug 27, 2024Aug 27, 2024
    • HexaLocker ransomware analysis
      YARA
      GNU Affero General Public License v3.0
      0200Updated Aug 23, 2024Aug 23, 2024
    • Python
      Other
      1512733Updated Aug 16, 2024Aug 16, 2024
    • frinet

      Public
      Frida-based tracer for easier reverse-engineering on Android, iOS, Linux, Windows and most related architectures.
      C
      MIT License
      4546650Updated Aug 7, 2024Aug 7, 2024
    • Finding Java gadget chains with CodeQL
      CodeQL
      GNU General Public License v3.0
      1815900Updated Jul 26, 2024Jul 26, 2024
    • A simple Toolkit to BF and decrypt Windows EntraId CacheData
      Python
      01300Updated Jun 20, 2024Jun 20, 2024
    • DLHell

      Public
      Local & remote Windows DLL Proxying
      Python
      2216000Updated Jun 17, 2024Jun 17, 2024
    • Python
      0600Updated Jun 4, 2024Jun 4, 2024
    • A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.
      Python
      Other
      1622800Updated Jun 2, 2024Jun 2, 2024
    • A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.
      PowerShell
      1311710Updated May 13, 2024May 13, 2024
    • OUned

      Public
      The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning
      Python
      117810Updated Apr 17, 2024Apr 17, 2024
    • EIPP

      Public
      Entra ID Password Protection Banned Password Lists
      C#
      11300Updated Apr 16, 2024Apr 16, 2024