
HiveJack
This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

DejaVU - Open Source Deception Framework

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

A basic emulation of an "RPC Backdoor"

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…


Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…

Dump Kerberos tickets from the KCM database of SSSD

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Common library for tools implementing GPO attack vectors