chebuya / exploits
Repo for all my exploits/PoCs
☆50Updated last week
Alternatives and similar repositories for exploits
Users that are interested in exploits are comparing it to the libraries listed below
Sorting:
- ☆56Updated 6 months ago
- A GUI wrapper inside of Havoc to interact with bloodhound CE☆71Updated last year
- List of some AD tools I frequently use☆45Updated 3 months ago
- A Moodle Scanner☆40Updated 5 months ago
- ☆58Updated 7 months ago
- The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere, ANY IP, ANY PORT and ANY APPLICATION.☆61Updated 8 months ago
- ☆85Updated 3 months ago
- RCE PoC for Empire C2 framework <5.9.3☆26Updated last year
- this script adds the ability to encode shellcode (.bin) in XOR,chacha20, AES. You can choose between 2 loaders (Myph / 221b)☆82Updated last year
- Retrieve LAPS passwords from a domain. The tools is inspired in pyLAPS.☆82Updated 2 months ago
- Shellcode Tester Pro is a graphical interface tool for analysis, simulated execution, and reverse engineering of malicious shellcodes.☆29Updated last month
- PowerShell script to generate ShellCode in various formats☆41Updated 7 months ago
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆40Updated 11 months ago
- Inject RDPThief into memory with PowerShell.☆63Updated 3 months ago
- Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets. It uses RC4 encryption and Reed-Sol…☆93Updated last month
- SANS Workshop: Active Directory Privilege Escalation with Empire!☆29Updated last month
- ☆38Updated 3 weeks ago
- Fully automated windows credentials dumper, for SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with…☆75Updated 5 months ago
- A modification to fortra's CVE-2023-28252 exploit, compiled to exe☆53Updated last year
- Burp Suite Extension for inserting a magic byte into responder's request☆24Updated last year
- Exploit AD CS misconfiguration allowing privilege escalation and persistence from any child domain to full forest compromise☆95Updated last year
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆164Updated 5 months ago
- CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow☆24Updated 10 months ago
- Situational Awareness script to identify how and where to run implants☆49Updated 5 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆90Updated 10 months ago
- Duplicate not owned Token from Running Process☆72Updated last year
- exfiltration/infiltration toolkit☆23Updated last year
- Opsec tool for finding user sessions by analyzing event log files through RPC (MS-EVEN)☆67Updated 11 months ago
- ☆83Updated 3 months ago
- Tool to extract username and password of current user from PanGPA in plaintext☆84Updated 4 months ago