Stars
A byte code analyzer for finding deserialization gadget chains in Java applications
基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
AI-powered modular Active Directory red-team framework for authorized penetration testing, AD enumeration, attack-path analysis, Kerberos/ADCS workflows, reporting, operator automation, and MCP ser…
A comprehensive dataset of 1.1 billion trading records from Polymarket, processed into multiple analysis-ready formats. Features cleaned data, unified token perspectives, and user-level transformat…
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
CredsHunter - Credential Hunting scripts for Windows and Linux OS
Another BYOVD process killer. works on all EDR's. fully signed.
Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-si…
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)
Google and deepl translated conti leaks, which is shared by a member of the conti ransomware group.
Leaked pentesting manuals given to Conti ransomware crooks
Fast Rust scanner to find leaked API keys on GitHub - OpenAI, Anthropic, Claude, GPT, AWS, Stripe, HuggingFace + 45 providers. Verify active secrets instantly.
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-32…
🚀 Free HTTP, SOCKS4, & SOCKS5 proxy list * Updated every 5 minutes * and rotating proxy API (100+ countries)
XOR decrypting shellcode using the GPU with OpenCL. Original PoC adopted by e.g. CoffeeLoader, GpuGate.