
Prox-Ez
HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Create fake certs for binaries using windows binaries and the power of bat files

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Havoc C2 plugin that creates a hidden Windows desktop, streams it to a browser viewer, and injects mouse/keyboard input for covert remote control.

Decrypt GlobalProtect configuration and cookie files.

Manipulating and Abusing Windows Access Tokens.

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

RunasCs - Csharp and open version of windows builtin runas.exe

Stop Windows Defender programmatically

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

A windows token impersonation tool

Spoof file icons and extensions in Windows

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

A C# implementation of dumping credentials from Windows Credential Manager