
PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework

PowerSploit - A PowerShell Post-Exploitation Framework

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A C2 post-exploitation framework

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Lateral Movement Using DCOM and DLL Hijacking

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

Code execution/injection technique using DLL PEB module structure manipulation

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.


Local & remote Windows DLL Proxying

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.


The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…


DLL Planting in the Slack 4.33.73 - CVE-2023-38820