
lsarelayx
System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

Windows Exploit Suggester - Next Generation

DCOM-based privilege escalation tool for Windows Server 2012-2022 and Windows 8-11, elevating users with ImpersonatePrivilege to NT AUTHORITY\SYSTEM…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

LLVM based static binary analysis framework

A Bind Shell Using the Fax Service and a DLL Hijack

Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087…

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities

Using CVE-2023-21768 to manual map kernel mode driver

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Cobalt Strike aggressor script implementing CVE-2020-0796 local privilege escalation via reflective DLL injection for Windows 10 and Server 1903/1909.

Local privilege escalation exploit for Symantec Endpoint Protection (CVE-2019-12750) targeting x64 Windows systems, based on published vulnerability…

Proof-of-concept exploit for CVE-2020-10665 demonstrating local privilege escalation in Docker Desktop for Windows via hardlink-based arbitrary file…