
CVE-2026-8181
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

RunasCs - Csharp and open version of windows builtin runas.exe

Phishing with a fake reCAPTCHA

C# Reflective loader for unmanaged binaries.

Ask a TGS on behalf of another user without password

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

A C# implementation of dumping credentials from Windows Credential Manager

Impersonate Logged In Accounts & Execute Commands

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

real time face swap and one-click video deepfake with only a single image

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate