
Py-RDP-Patcher
Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/


Check for valid credentials across a network over SMB

Manipulating and Abusing Windows Access Tokens.

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Windows Session Hijacking via COM

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Tools and Techniques for Red Team / Penetration Testing

A Bypass Anti-virus Software Lateral Movement Command Execution Tool

The Shadow Attack Framework

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

PowerSploit - A PowerShell Post-Exploitation Framework