
Nac_Bypass_Agent
This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Manipulating and Abusing Windows Access Tokens.

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Impersonate Logged In Accounts & Execute Commands

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

A C# implementation of dumping credentials from Windows Credential Manager

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

RunasCs - Csharp and open version of windows builtin runas.exe

Scripts to clone CA certificates for use in HTTPS client attacks.

This is a SMS And Call Bomber For Linux And Termux

Pass the Hash to a named pipe for token Impersonation

Leverage WindowsApp createdump tool to obtain an lsass dump

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

A windows token impersonation tool