-
CVE-2025-33073 Public
Forked from mverschu/CVE-2025-33073PoC Exploit for the NTLM reflection SMB flaw.
Python UpdatedJun 15, 2025 -
HexDnsEchoT Public
Forked from A0WaQ4/HexDnsEchoT命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)
Python UpdatedMar 27, 2023 -
JNDI-Inject-Exploit Public
Forked from exp1orer/JNDI-Inject-Exploit解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入
Java MIT License UpdatedJan 26, 2022 -
noPac Public
Forked from Ridter/noPacExploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
Python UpdatedDec 20, 2021 -
MemoryShellLearn Public
Forked from bitterzzZZ/MemoryShellLearn分享几个直接可用的内存马,记录一下学习过程中看过的文章
-
template-injection-workshop Public
Forked from GoSecure/template-injection-workshopCSS UpdatedDec 21, 2020 -
minhook Public
Forked from TsudaKageyu/minhookThe Minimalistic x86/x64 API Hooking Library for Windows
C Other UpdatedDec 12, 2020 -
-
red-kube Public
Forked from lightspin-tech/red-kubeRed Team KubeCTL Cheat Sheet
Apache License 2.0 UpdatedNov 10, 2020 -
-
LOLBAS Public
Forked from LOLBAS-Project/LOLBASLiving Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
XSLT UpdatedJul 23, 2020 -
BurpCrypto Public
Forked from whwlsfb/BurpCryptoBurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).
Java MIT License UpdatedJun 23, 2020 -
coremail-address-book Public
Forked from dpu/coremail-address-book📧Coremail邮件系统组织通讯录导出脚本
-
-
SharpAddDomainMachine Public
Forked from Ridter/SharpAddDomainMachineSharpAddDomainMachine
C# UpdatedMar 21, 2020 -
Adamantium-Thief Public
Forked from LimerBoy/Adamantium-ThiefDecrypt chromium based browsers passwords, cookies, credit cards, history, bookmarks. Version > 80 is supported.
C# UpdatedMar 17, 2020 -
CVE-2020-0688 Public
Forked from zcgonvh/CVE-2020-0688Exploit and detect tools for CVE-2020-0688
-
CNVD-2020-10487-Tomcat-Ajp-lfi Public
Forked from YDHCUI/CNVD-2020-10487-Tomcat-Ajp-lfiTomcat-Ajp协议文件读取漏洞
-
mssqlproxy Public
Forked from blackarrowsec/mssqlproxymssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse.
Python Other UpdatedFeb 13, 2020 -
-
fastjson_rce_tool Public
Forked from wyzxxz/jndi_toolfastjson_rce工具,不用搭建HTTP服务,不受JDK版本限制
-
Fake-flash.cn Public
Forked from r00tSe7en/Fake-flash.cnwww.flash.cn 的钓鱼页,中文+英文
-
CVE-2019-11932 Public
Forked from dorkerdevil/CVE-2019-11932double-free bug in WhatsApp exploit poc
C UpdatedOct 3, 2019 -
CVE-2019-11539 Public
Forked from 0xDezzy/CVE-2019-11539Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect
Python GNU General Public License v3.0 UpdatedSep 4, 2019 -
loginlog_windows Public
Forked from uknowsec/loginlog_windows读取登录过本机的登录失败或登录成功的所有计算机信息,快速定位运维管理人员。 Reference: https://github.com/ysrc/yulong-hids
2 UpdatedAug 29, 2019 -
K8tools Public
Forked from k8gege/K8toolsK8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetN…
-
pyinstaller Public
Forked from pyinstaller/pyinstallerFreeze (package) Python programs into stand-alone executables
Python Other UpdatedJul 28, 2019 -
scrun Public
Forked from k8gege/scrunBypassAV ShellCode Loader (Cobaltstrike/Metasploit)
-
pywinrm Public
Forked from diyan/pywinrmPython library for Windows Remote Management (WinRM)
Python MIT License UpdatedJul 11, 2019 -
redis-rogue-server Public
Forked from n0b0dyCN/redis-rogue-serverRedis(<=5.0.5) RCE
C Apache License 2.0 UpdatedJul 10, 2019