
RunPE
C# Reflective loader for unmanaged binaries.

C# Reflective loader for unmanaged binaries.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Manipulating and Abusing Windows Access Tokens.

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

RunasCs - Csharp and open version of windows builtin runas.exe

Stop Windows Defender programmatically

A windows token impersonation tool

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate

Ask a TGS on behalf of another user without password

Some scripts to abuse kerberos using Powershell

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

A C# implementation of dumping credentials from Windows Credential Manager

Phishing with a fake reCAPTCHA

Decrypt GlobalProtect configuration and cookie files.