
Maestro
Abusing Azure services over C2

Abusing Azure services over C2

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

evilginx3 + gophish

Dominate Active Directory with PowerShell.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

Python3 tool to perform password spraying using RDP

Proof-of-concept tool that coerces Windows authentication via MS-DFSNM NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods for credential relay…

Take security by obscurity to the next level (this is a bad idea, don't really use this please)

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

Asynchronous Password Spraying Tool in C# for Windows Environments


Ask the Web Account Manager (WAM) for Entra ID tokens