
SharpNamedPipePTH
Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

This is Advance Phishing Tool ! OTP PHISHING

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Leverage WindowsApp createdump tool to obtain an lsass dump

Manipulating and Abusing Windows Access Tokens.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

A DNS spoofer tool written in Python3.

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Ask a TGS on behalf of another user without password

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate