
ruler
A tool to abuse Exchange services

A tool to abuse Exchange services

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库…

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Windows Privilege Escalation from User to Domain Admin.

Microsoft-Outlook-Remote-Code-Execution-Vulnerability


Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).


Process injection alternative

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…