
impersonate
Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.
adversarial-attackimpersonation-toolslateral-movement+3
329

Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.

Terminates AV/EDR processes by exploiting the vulnerable Gmer driver via BYOVD. Requires admin privileges; intended for red-team engagements.

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…