Starred repositories
Universal and Transferable Attacks on Aligned Language Models
[CCS'24] A dataset consists of 15,140 ChatGPT prompts from Reddit, Discord, websites, and open-source datasets (including 1,405 jailbreak prompts).
Awesome-Jailbreak-on-LLMs is a collection of state-of-the-art, novel, exciting jailbreak methods on LLMs. It contains papers, codes, datasets, evaluations, and analyses.
The official implementation of our pre-print paper "Automatic and Universal Prompt Injection Attacks against Large Language Models".
Safety at Scale: A Comprehensive Survey of Large Model Safety
The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems.
Kerberos unconstrained delegation abuse toolkit
Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys
A security assessment tool for analyzing Active Directory Group Policy Objects (GPOs) to identify misconfigurations and vulnerabilities
List of Stuff I did to get through the OSCP :D
Automation for internal Windows Penetrationtest / AD-Security
Fork of BloodHound with PKI nodes and edges for Certipy along with some minor personal improvements
Introductory guide on the configuration and subsequent exploitation of Active Directory Certificate Services with Certipy. Based on the white paper Certified Pre-Owned.
Tool for Active Directory Certificate Services enumeration and abuse
Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.
Kernel mode WinDbg extension and PoCs for token privilege investigation.
A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
🔓 Padding oracle attack against PKCS7 🔓
A tool to dump the login password from the current linux user
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).