
CS-Remote-OPs-BOF
Remote operations commands implemented using Beacon Object Files

Remote operations commands implemented using Beacon Object Files

Secure offline storage of credentials with encrypted vaults, password generator, TOTP, YubiKey/OnlyKey support, browser integration, and CLI.

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Desktop application to register a Signal account and link Signal Desktop without requiring a smartphone, using Signal's cryptographic protocols for…

Reproduction of cve-2024-1708-connectwise_rce_reproduction

A TryHackme room covering the CVE-2025-53779 exploitation using windows

A tool for checking if MFA is enabled on multiple Microsoft Services

Portable, hardware-backed WebAuthn credentials using TPM 2.0. Deterministic parent key derived from a master seed enables cross-device credential…

Orb is a secure, terminal-first utility that allows you to share a local folder across the internet using end-to-end encryption. No accounts, no…

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Emulates NIST SP 800-73 PIV smart cards on Windows using a PFX certificate and private key, enabling smart-card authentication for RDP, Citrix, and…

Python3 tool to perform password spraying using RDP

Detects forged Kerberos tickets by dumping session and ticket data, scoring anomalies, and generating Windows event-log indicators for SIEM-based…

Proof-of-concept tool that coerces Windows authentication via MS-DFSNM NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods for credential relay…

Detects NTLM relay attacks via PetitPotam exploit using Zeek, distinguishing successful and unsuccessful attempts by analyzing DCERPC return codes.

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.