
Titanis
Windows protocol library, including SMB and RPC implementations, among others.

Windows protocol library, including SMB and RPC implementations, among others.

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

The DCERPC only printerbug.py version

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

Local SYSTEM auth trigger for relaying

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

Windows Privilege Escalation from User to Domain Admin.

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…