
RAITrigger
Local SYSTEM auth trigger for relaying

Local SYSTEM auth trigger for relaying

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Rusty Impersonate

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Exploitation of CVE-2025-29969

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

PoC exploit code for CVE-2021-26855

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

Proof-of-concept exploit for CVE-2021-33766 (ProxyToken) authentication bypass in Microsoft Exchange Server. Supports single and batch target…