
ad-autopwn
Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

A script to automate keystrokes through a graphical desktop program.

Exploiting Parsec for Windows to gain SYSTEM privileges

Proof-of-concept exploit for CVE-2020-27955 in Git-LFS, demonstrating remote code execution via a crafted git clone operation to obtain a reverse…

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

Self-developed tools for Lateral Movement/Code Execution

Network Pivoting Toolkit

TCP Port Redirection Utility

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

The DCERPC only printerbug.py version

A basic emulation of an "RPC Backdoor"

Automated 802.1x Bypass

CVE-2025-33053 Proof Of Concept (PoC)