federicodotta / ysoserialLinks
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
☆43Updated 5 years ago
Alternatives and similar repositories for ysoserial
Users that are interested in ysoserial are comparing it to the libraries listed below
Sorting:
- This code was used for the blogpost on secjuice.☆42Updated 6 years ago
- Python3 tool to perform password spraying against Microsoft Online service using various methods☆86Updated 2 years ago
- A Red Team tool for exfiltrating sensitive data from Confluence pages.☆113Updated 2 years ago
- Powershell module to get the NetNTLMv2 hash of the current user☆96Updated 3 years ago
- A tool to password spray Jenkins instances☆59Updated 6 years ago
- A tool for creating proxy dll for hijacking☆42Updated last year
- Exchangelib wrapper for pentesting☆67Updated 10 months ago
- A list of "secrets" from JWT sample code and readme files.☆57Updated 5 years ago
- Registry permission scanner written in C# for finding potential privesc avenues within registry☆86Updated 4 years ago
- This script is a multi-threaded Okta password sprayer.☆71Updated last year
- Add SD for controlled computer object to a target object for RBCD using LDAP☆37Updated 4 years ago
- Password Spraying Script detecting current and previous passwords of Active Directory User☆66Updated 4 years ago
- named pipe server with impersonation☆60Updated 6 years ago
- Loads a custom dll in system32 via diaghub.☆82Updated 5 years ago
- ☆17Updated 4 years ago
- Vulnerable webapp testbed☆24Updated 9 years ago
- "Powershell script assisting with domain enumerating and in finding quick wins" - Basically written while doing the 'Advanced Red Team' l…☆82Updated 4 years ago
- ☆39Updated 10 months ago
- PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10…☆35Updated 3 years ago
- offensive notes & resources☆42Updated 8 months ago
- A mirror of several precompiled standalone red-teaming tools.☆19Updated 2 years ago
- Checks for signature requirements over LDAP☆98Updated 3 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing☆90Updated 5 years ago
- Iterative AD discovery toolkit for offensive operations☆85Updated 5 years ago
- ☆10Updated 4 years ago
- A Red Team tool for exfiltrating sensitive data from Jira tickets.☆86Updated 2 years ago
- ☆46Updated 8 years ago
- Script and resources to execute shell commands using access to a PostgreSQL service☆70Updated 8 years ago
- A collection of Neo4j/BloodHound queries to collect interesting information.☆46Updated 3 years ago
- Python Script to Exploit SpoolService/Printer Bug on Exchange - Thanks to @3xocyte☆21Updated 6 years ago