
SharpNamedPipePTH
Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Ask a TGS on behalf of another user without password

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Manipulating and Abusing Windows Access Tokens.

Pass the Hash to a named pipe for token Impersonation

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Decrypt GlobalProtect configuration and cookie files.

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Rusty Impersonate

Leverage WindowsApp createdump tool to obtain an lsass dump

A C# utility for interacting with SCOM

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

A C# implementation of dumping credentials from Windows Credential Manager

Impersonate Logged In Accounts & Execute Commands