praetorian-inc / proxylogon-exploit
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
☆45Updated 3 years ago
Related projects: ⓘ
- ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassin…☆30Updated 3 years ago
- ☆99Updated 3 years ago
- Exploiting CVE-2021-44228 in vCenter for remote code execution and more.☆100Updated 2 years ago
- Impacket is a collection of Python classes for working with network protocols.☆40Updated 3 years ago
- "Powershell script assisting with domain enumerating and in finding quick wins" - Basically written while doing the 'Advanced Red Team' l…☆79Updated 3 years ago
- CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit☆155Updated 3 years ago
- ☆31Updated 2 years ago
- PickleC2 is a post-exploitation and lateral movements framework☆83Updated 3 years ago
- RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2☆59Updated 3 years ago
- Some random tools I use for penetration testing☆82Updated 3 weeks ago
- Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it …☆156Updated 3 years ago
- Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207☆108Updated last year
- Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands i…☆109Updated 2 years ago
- The vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment …☆42Updated 2 years ago
- CVE-2021-40444☆63Updated 2 years ago
- C# tool to discover low hanging fruits☆88Updated last year
- Microsoft Exchange password spray tool with proxy support.☆40Updated 3 years ago
- A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impers…☆156Updated 2 years ago
- Automatic ProxyShell Exploit☆114Updated 3 years ago
- ☆203Updated 3 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing☆91Updated 4 years ago
- A Web-UI for subdomain enumeration (subfinder)☆53Updated 4 years ago
- CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD☆69Updated 2 years ago
- Impacket is a collection of Python classes for working with network protocols.☆39Updated 2 years ago
- Exploit and Check Script for CVE 2022-1388☆58Updated 2 years ago
- Convert Cobalt Strike profiles to IIS web.config files☆109Updated 3 years ago
- ☆92Updated last year
- Extendable payload obfuscation and delivery framework☆140Updated last year
- Checks for signature requirements over LDAP☆92Updated last year
- pFuzz helps us to bypass web application firewall by using different methods at the same time.☆156Updated 3 years ago