
SharpNamedPipePTH
Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

Manipulating and Abusing Windows Access Tokens.

Pass the Hash to a named pipe for token Impersonation

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Rust Windows token impersonation utility that duplicates process tokens, executes commands as arbitrary users via named pipe output, and enables…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Scripts to clone CA certificates for use in HTTPS client attacks.

Phishing page source code mimicking official Flash Player download site (flash.cn) to trick users into downloading malicious payload. Supports…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Cookie-stealing exploit for Vehicle Service Management System 1.0 enabling full account takeover via malicious HTML file upload and session hijacking.

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

C# Reflective loader for unmanaged binaries.

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

Automates Windows domain Kerberos relay attacks to achieve local privilege escalation via RBCD, Shadow Credentials, or ADCS web enrollment, then…

Single-file HTML harness that recreates the ClickFix phishing lure with a realistic fake reCAPTCHA, tricking users into pasting a malicious command…

Ask a TGS on behalf of another user without password