
OUned
The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

A little tool to play with the Seclogon service

Ask a TGS on behalf of another user without password

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Lateral Movement Using DCOM and DLL Hijacking

CVE-2019-1040 with Exchange

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

An automated SMB relay exploitation script.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Exploit for the CVE-2023-23397

PrintNightmare (CVE-2021-34527) PoC Exploit

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Local & remote Windows DLL Proxying

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…