
KrbRelayUp
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Windows Privilege Escalation from User to Domain Admin.

Partial python implementation of SharpGPOAbuse

Persistent XSS on Comtrend AR-5387un router

Tools and Techniques for Red Team / Penetration Testing

A tool to abuse Exchange services

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…


Ask a TGS on behalf of another user without password