
UAC-bypass
PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

Simple (relatively) things allowing you to dig a bit deeper than usual.

Bypass llm guardrails by confusing it with fabricated tool output.

This is the tool to dump the LSASS process on modern Windows 11

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Bypassing UAC with SSPI Datagram Contexts

PrintNotifyPotato

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

A POC to disable TamperProtection and other Defender / MDE components

Public Repo for Atomic Test Harness

A simple ptrace-less shared library injector for x64 Linux

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Windows 7 UAC Bypass Vulnerability in the Windows Script Host

Detect EDR's exceptions by inspecting processes' loaded modules

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

Windows And Ways To Break It

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…